← Vulnerability feed

Vulnerability record · CVE-2023-38992 · published 28 July 2023

CVE-2023-38992: Jeecg-Boot SQL injection in dict loadTreeData title parameter

Jeecg · Jeecg Boot

Jeecg-Boot v3.5.1 contains a SQL injection flaw in the title parameter of the /sys/dict/loadTreeData endpoint. Because the endpoint is network-reachable and the injection is unauthenticated, an attacker can manipulate backend SQL queries directly. This matters because it exposes the application's database to full read and write compromise.

9.8 CVSS 3.1 Critical EPSS 73% · top 0.5% CWE-89 · SQL injection
9.8CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network SQL injection with a 9.8 CVSS score and very high EPSS probability makes this an urgent patch target.

What it is

Jeecg-Boot v3.5.1 contains a SQL injection flaw in the title parameter of the /sys/dict/loadTreeData endpoint. Because the endpoint is network-reachable and the injection is unauthenticated, an attacker can manipulate backend SQL queries directly. This matters because it exposes the application's database to full read and write compromise.

Impact

An attacker can read, modify, or delete arbitrary data the database account can access, and potentially execute database-level commands. With confidentiality, integrity, and availability all rated high, a successful hit can fully compromise the application's data layer.

Attack surface

The flaw is reached over the network via the title parameter at /sys/dict/loadTreeData. The CVSS vector shows PR:N and UI:N, meaning no authentication and no user interaction are required.

Exploitation

No CISA KEV listing and no ransomware association are recorded. EPSS is very high at 0.734 (99.4th percentile), and the reference is tagged Exploit and Patch, indicating public exploit material exists.

What to do

  • Apply the vendor patch referenced in the jeecg-boot issue 5173, or upgrade past v3.5.1.
  • If patching is delayed, restrict network access to /sys/dict/loadTreeData to trusted administrative networks.
  • Use parameterized queries or strict input validation for the title parameter in any custom code.
  • Run the application's database account with least privilege to limit injection impact.
  • Monitor and rotate database credentials if compromise is suspected.

Detection

  • Inspect web and application logs for requests to /sys/dict/loadTreeData with SQL metacharacters in the title parameter.
  • Alert on database errors or unusual query patterns originating from the application.
  • Baseline normal title parameter values and flag deviations or encoded payloads.
  • Watch for outbound database connections or data exfiltration from the application host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-38992 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-40489Jeecg boot code injection vulnerabilityThere is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary…EPSS 0.52%9.8CVE-2024-43028Jeecg boot command injection vulnerabilityA command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a cra…EPSS 1.5%9.8CVE-2024-48307Jeecg boot sql injection vulnerabilityJeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.EPSS 44%9.8CVE-2023-41544Jeecg boot code injection vulnerabilitySSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport…EPSS 2.7%9.8CVE-2023-41542Jeecg boot sql injection vulnerabilitySQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmre…EPSS 0.86%9.8CVE-2023-41543Jeecg boot sql injection vulnerabilitySQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /…EPSS 0.93%9.8CVE-2023-40989Jeecg boot sql injection vulnerabilitySQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the …EPSS 2.2%9.8CVE-2023-42268Jeecg boot sql injection vulnerabilityJeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.EPSS 0.91%

Source: NIST National Vulnerability Database (record CVE-2023-38992), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.