Lucene search

K

J2eefast Security Vulnerabilities

cve
cve

CVE-2023-2475

A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown processing of the component System Message Handler. The manipulation of the argument 主题 leads to cross site scripting. The attack may be initiated remotely. The exploit has been....

5.4CVSS

5.2AI Score

0.001EPSS

2023-05-02 01:15 PM
21
cve
cve

CVE-2023-2476

A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown function of the component Announcement Handler. The manipulation of the argument 系统工具/公告管理 leads to cross site scripting. It is possible to launch the attack remotely. The...

5.4CVSS

5.3AI Score

0.001EPSS

2023-05-02 02:15 PM
24
cve
cve

CVE-2021-28890

J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL...

9.8CVSS

9.8AI Score

0.002EPSS

2021-08-12 10:15 PM
32