Skip to content
Noroxi

j2eefast records

21 published records for vendor j2eefast.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 21
  2. 23
  3. 24

Bar: total · dark part: CISA KEV.

All records

21 records
  • J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to

    CriticalCVSS 9.8No exploitEPSS 1%

    j2eefast · j2eefastAug 12, 2021

  • In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in a

    CriticalCVSS 9.8No exploitEPSS 1%

    j2eefast · j2eefastOct 18, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.

    CriticalCVSS 9.8No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.

    CriticalCVSS 9.8No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.

    CriticalCVSS 9.8No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .

    CriticalCVSS 9.8No exploitEPSS 1%

    j2eefast · j2eefastMay 23, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.

    CriticalCVSS 9.8No exploitEPSS 0%

    j2eefast · j2eefastMay 23, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.

    CriticalCVSS 9.8No exploitEPSS 0%

    j2eefast · j2eefastMay 23, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.

    CriticalCVSS 9.1No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.

    HighCVSS 8.8No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in

    HighCVSS 8.8No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml.

    HighCVSS 8.8No exploitEPSS 0%

    j2eefast · j2eefastMay 23, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.

    HighCVSS 8.1No exploitEPSS 0%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.

    HighCVSS 8.2No exploitEPSS 0%

    j2eefast · j2eefastMay 23, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

    HighCVSS 7.5No exploitEPSS 1%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

    HighCVSS 7.3No exploitEPSS 0%

    j2eefast · j2eefastMay 7, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.

    MediumCVSS 6.3No exploitEPSS 0%

    j2eefast · j2eefastMay 23, 2024

  • CVE-2023-2476
    21Monitor

    Dromara J2eeFAST Announcement cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    j2eefast · j2eefastMay 2, 2023

  • CVE-2023-2475
    21Monitor

    Dromara J2eeFAST System Message cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    j2eefast · j2eefastMay 2, 2023

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.

    MediumCVSS 5.4No exploitEPSS 0%

    j2eefast · j2eefastMay 23, 2024

  • J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.

    MediumCVSS 5.3No exploitEPSS 0%

    j2eefast · j2eefastMay 7, 2024