Skip to content

Instantly share code, notes, and snippets.

@kaliwin
Last active August 29, 2023 03:43
Show Gist options
  • Save kaliwin/9d6cf58bb6ec06765cdf7b75e13ee460 to your computer and use it in GitHub Desktop.
Save kaliwin/9d6cf58bb6ec06765cdf7b75e13ee460 to your computer and use it in GitHub Desktop.
CVE-2023-40787
CVE-2023-40787
[description]
In SpringBlade V3.6.0 when executing SQL query, the parameters
submitted by the user are not wrapped in quotation marks, which leads to SQL injection
[Vulnerability Type]
SQL Injection
[Vendor of Product]
https://github.com/chillzhuang/SpringBlade
[Affected Product Code Base]
SpringBlade - V3.6.0
[Attack Type]
Remote
[Discoverer]
cyvk
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment