j2eefast records
21 published records for vendor j2eefast.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')18
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2021-28890No exploit | J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 1.3% | Aug 12, 2021 |
39Monitor | CVE-2024-45944No exploit | In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in aj2eefast · j2eefast | Critical9.8 | — | 0.9% | Oct 18, 2024 |
39Monitor | CVE-2024-33164No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 0.6% | May 7, 2024 |
39Monitor | CVE-2024-33153No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 0.6% | May 7, 2024 |
39Monitor | CVE-2024-33155No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 0.6% | May 7, 2024 |
39Monitor | CVE-2024-35086No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 0.5% | May 23, 2024 |
39Monitor | CVE-2024-35084No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 0.4% | May 23, 2024 |
39Monitor | CVE-2024-35091No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.j2eefast · j2eefast · CWE-89 | Critical9.8 | — | 0.4% | May 23, 2024 |
36Monitor | CVE-2024-33146No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.j2eefast · j2eefast · CWE-89 | Critical9.1 | — | 0.5% | May 7, 2024 |
35Monitor | CVE-2024-33147No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.j2eefast · j2eefast · CWE-89 | High8.8 | — | 0.5% | May 7, 2024 |
35Monitor | CVE-2024-33144No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function inj2eefast · j2eefast · CWE-89 | High8.8 | — | 0.5% | May 7, 2024 |
35Monitor | CVE-2024-35083No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml.j2eefast · j2eefast · CWE-89 | High8.8 | — | 0.4% | May 23, 2024 |
32Monitor | CVE-2024-33149No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.j2eefast · j2eefast · CWE-89 | High8.1 | — | 0.5% | May 7, 2024 |
32Monitor | CVE-2024-35090No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.j2eefast · j2eefast · CWE-89 | High8.2 | — | 0.3% | May 23, 2024 |
30Monitor | CVE-2024-33139No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.j2eefast · j2eefast · CWE-89 | High7.5 | — | 0.5% | May 7, 2024 |
29Monitor | CVE-2024-33148No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.j2eefast · j2eefast · CWE-89 | High7.3 | — | 0.4% | May 7, 2024 |
25Monitor | CVE-2024-35082No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.j2eefast · j2eefast · CWE-89 | Medium6.3 | — | 0.3% | May 23, 2024 |
21Monitor | CVE-2023-2476No exploit | Dromara J2eeFAST Announcement cross site scriptingj2eefast · j2eefast · CWE-79 | Medium5.4 | — | 0.5% | May 2, 2023 |
21Monitor | CVE-2023-2475No exploit | Dromara J2eeFAST System Message cross site scriptingj2eefast · j2eefast · CWE-79 | Medium5.4 | — | 0.5% | May 2, 2023 |
21Monitor | CVE-2024-35085No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.j2eefast · j2eefast · CWE-89 | Medium5.4 | — | 0.2% | May 23, 2024 |
21Monitor | CVE-2024-33161No exploit | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.j2eefast · j2eefast · CWE-89 | Medium5.3 | — | 0.2% | May 7, 2024 |
- CVE-2021-2889039Monitor
J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to
CriticalCVSS 9.8No exploitEPSS 1%j2eefast · j2eefastAug 12, 2021
- CVE-2024-4594439Monitor
In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in a
CriticalCVSS 9.8No exploitEPSS 1%j2eefast · j2eefastOct 18, 2024
- CVE-2024-3316439Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.
CriticalCVSS 9.8No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3315339Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.
CriticalCVSS 9.8No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3315539Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.
CriticalCVSS 9.8No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3508639Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .
CriticalCVSS 9.8No exploitEPSS 1%j2eefast · j2eefastMay 23, 2024
- CVE-2024-3508439Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.
CriticalCVSS 9.8No exploitEPSS 0%j2eefast · j2eefastMay 23, 2024
- CVE-2024-3509139Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
CriticalCVSS 9.8No exploitEPSS 0%j2eefast · j2eefastMay 23, 2024
- CVE-2024-3314636Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
CriticalCVSS 9.1No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3314735Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.
HighCVSS 8.8No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3314435Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in
HighCVSS 8.8No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3508335Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml.
HighCVSS 8.8No exploitEPSS 0%j2eefast · j2eefastMay 23, 2024
- CVE-2024-3314932Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.
HighCVSS 8.1No exploitEPSS 0%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3509032Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.
HighCVSS 8.2No exploitEPSS 0%j2eefast · j2eefastMay 23, 2024
- CVE-2024-3313930Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
HighCVSS 7.5No exploitEPSS 1%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3314829Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.
HighCVSS 7.3No exploitEPSS 0%j2eefast · j2eefastMay 7, 2024
- CVE-2024-3508225Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.
MediumCVSS 6.3No exploitEPSS 0%j2eefast · j2eefastMay 23, 2024
- CVE-2023-247621Monitor
Dromara J2eeFAST Announcement cross site scripting
MediumCVSS 5.4No exploitEPSS 1%j2eefast · j2eefastMay 2, 2023
- CVE-2023-247521Monitor
Dromara J2eeFAST System Message cross site scripting
MediumCVSS 5.4No exploitEPSS 1%j2eefast · j2eefastMay 2, 2023
- CVE-2024-3508521Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.
MediumCVSS 5.4No exploitEPSS 0%j2eefast · j2eefastMay 23, 2024
- CVE-2024-3316121Monitor
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.
MediumCVSS 5.3No exploitEPSS 0%j2eefast · j2eefastMay 7, 2024