{"advisories":[{"id":"GHSA-mcw3-h5xg-r95m","source":"ghsa","title":"JeecgBoot SQL Injection vulnerability","url":"https://github.com/advisories/GHSA-mcw3-h5xg-r95m"}],"cve":"CVE-2024-48307","epss":{"score":0.44335},"mitre":{"cpes":[],"created":"2024-10-31T00:00:00+00:00","description":"JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2024/48xxx/CVE-2024-48307.json","references":["https://github.com/jeecgboot","https://github.com/jeecgboot/JeecgBoot","https://github.com/jeecgboot/JeecgBoot/issues/7237"],"title":null,"updated":"2024-10-31T18:33:55.964000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:jeecg:jeecg_boot:3.7.1:*:*:*:*:*:*:*"],"created":"2024-10-31T01:15:14.803000+00:00","description":"JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2024/CVE-2024-48307.json","references":["https://github.com/jeecgboot","https://github.com/jeecgboot/JeecgBoot","https://github.com/jeecgboot/JeecgBoot/issues/7237"],"title":null,"updated":"2026-06-17T07:58:24.880000+00:00","vendors":["jeecg","jeecg$PRODUCT$jeecg_boot"],"weaknesses":["CWE-89"]},"opencve":{"changes":[{"created":"2024-10-31T00:45:00+00:00","data":[{"details":{"new":"JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.","old":null},"type":"description"},{"details":{"added":["https://github.com/jeecgboot","https://github.com/jeecgboot/JeecgBoot","https://github.com/jeecgboot/JeecgBoot/issues/7237"],"removed":[]},"type":"references"}],"id":"155a55c4-2424-4c60-81bc-d2a0c7cf77bb"},{"created":"2024-10-31T19:15:00+00:00","data":[{"details":["jeecg","jeecg$PRODUCT$jeecgboot"],"type":"first_time"},{"details":{"added":["CWE-89"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:jeecg:jeecgboot:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["jeecg","jeecg$PRODUCT$jeecgboot"],"removed":[]},"type":"vendors"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"19d5e195-8682-44c7-aaae-5541c734e77c"},{"created":"2025-06-27T20:15:00+00:00","data":[{"details":["jeecg$PRODUCT$jeecg_boot"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:jeecg:jeecg_boot:3.7.1:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["jeecg$PRODUCT$jeecg_boot"],"removed":[]},"type":"vendors"}],"id":"48f99300-9fdb-49a9-b549-c8236c8fb428"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.89113},"old":{"score":0.89031}}}},"type":"metrics"}],"id":"62387b1a-f859-4cf8-bf08-57246508b1da"}],"cpes":{"data":["cpe:2.3:a:jeecg:jeecg_boot:3.7.1:*:*:*:*:*:*:*","cpe:2.3:a:jeecg:jeecgboot:*:*:*:*:*:*:*:*"],"providers":["nvd","vulnrichment"]},"created":{"data":"2024-10-31T00:00:00+00:00","provider":"mitre"},"description":{"data":"JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.44335},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/jeecgboot","https://github.com/jeecgboot/JeecgBoot","https://github.com/jeecgboot/JeecgBoot/issues/7237"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-06-27T19:45:28.870000+00:00","provider":"nvd"},"vendors":{"data":["jeecg","jeecg$PRODUCT$jeecg_boot","jeecg$PRODUCT$jeecgboot"],"providers":["nvd","vulnrichment"]},"weaknesses":{"data":["CWE-89"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":["cpe:2.3:a:jeecg:jeecgboot:*:*:*:*:*:*:*:*"],"created":"2024-10-31T00:00:00+00:00","description":"JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2024-10-31T18:33:51.009000+00:00","vendors":["jeecg","jeecg$PRODUCT$jeecgboot"],"vulnrichment_repo_path":"2024/48xxx/CVE-2024-48307.json","weaknesses":["CWE-89"]}}