logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-25330

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-25330

Description:
A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.
Last updated date:
08/02/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/14/2023
Reference url to background

https://github.com/FCncdn/MybatisPlusTenantPluginSQLInjection-POC/blob/master/Readme.en.md

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy