Vulnerability record · CVE-2023-38992 · published 28 July 2023
CVE-2023-38992: Jeecg-Boot SQL injection in dict loadTreeData title parameter
Jeecg · Jeecg Boot
Jeecg-Boot v3.5.1 contains a SQL injection flaw in the title parameter of the /sys/dict/loadTreeData endpoint. Because the endpoint is network-reachable and the injection is unauthenticated, an attacker can manipulate backend SQL queries directly. This matters because it exposes the application's database to full read and write compromise.
Description
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network SQL injection with a 9.8 CVSS score and very high EPSS probability makes this an urgent patch target.
What it is
Jeecg-Boot v3.5.1 contains a SQL injection flaw in the title parameter of the /sys/dict/loadTreeData endpoint. Because the endpoint is network-reachable and the injection is unauthenticated, an attacker can manipulate backend SQL queries directly. This matters because it exposes the application's database to full read and write compromise.
Impact
An attacker can read, modify, or delete arbitrary data the database account can access, and potentially execute database-level commands. With confidentiality, integrity, and availability all rated high, a successful hit can fully compromise the application's data layer.
Attack surface
The flaw is reached over the network via the title parameter at /sys/dict/loadTreeData. The CVSS vector shows PR:N and UI:N, meaning no authentication and no user interaction are required.
Exploitation
No CISA KEV listing and no ransomware association are recorded. EPSS is very high at 0.734 (99.4th percentile), and the reference is tagged Exploit and Patch, indicating public exploit material exists.
What to do
- Apply the vendor patch referenced in the jeecg-boot issue 5173, or upgrade past v3.5.1.
- If patching is delayed, restrict network access to /sys/dict/loadTreeData to trusted administrative networks.
- Use parameterized queries or strict input validation for the title parameter in any custom code.
- Run the application's database account with least privilege to limit injection impact.
- Monitor and rotate database credentials if compromise is suspected.
Detection
- Inspect web and application logs for requests to /sys/dict/loadTreeData with SQL metacharacters in the title parameter.
- Alert on database errors or unusual query patterns originating from the application.
- Baseline normal title parameter values and flag deviations or encoded payloads.
- Watch for outbound database connections or data exfiltration from the application host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/jeecgboot/jeecg-boot/issues/5173 | ExploitIssue TrackingPatch |
| https://github.com/jeecgboot/jeecg-boot/issues/5173 | ExploitIssue TrackingPatch |
Track CVE-2023-38992 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-38992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.