• Vulnerability code: HW21-0499
  • Product name: JeecgBoot low code platform
  • Problem: SQL injection 0day vulnerability exists in JECG system
  • Processed status: Processed
  • Treatment scheme: for the interface with SQL vulnerability injection risk, the security verification is carried out by adding signature authentication. Signing rules logic: interface parameters + custom key string (official release to modify themselves) + year, month, day, minute, second time stamp.
  • Patches download: https://pan.baidu.com/s/10SgP… Extract code: CY2Q