High severity8.8NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-43192
CVE-2023-43192
Description
SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement.
Affected products
3- cpe:2.3:a:jrecms:springbootcms:1.0:*:*:*:*:*:*:*
- SpringbootCMS/SpringbootCMSdescription
- Range: =1.0
Patches
Vulnerability mechanics
References
2- github.com/etn0tw/cve_sql/blob/main/jfinalcms_sql.mdnvdBroken LinkExploitThird Party Advisory
- github.com/etn0tw/cve_sql/blob/main/springbootcms_sql.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.