Home/Product/j2eefast
Product

j2eefast

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-45944
< 2.6.0
In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resu
9.8CRITICAL
CVE-2024-35091
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
9.8CRITICAL
CVE-2024-35090
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.
8.2HIGH
CVE-2024-35086
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .
9.8CRITICAL
CVE-2024-35085
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.
5.4MEDIUM
CVE-2024-35084
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.
9.8CRITICAL
CVE-2024-35083
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml.
8.8HIGH
CVE-2024-35082
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.
6.3MEDIUM
CVE-2024-33164
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() functio
9.8CRITICAL
CVE-2024-33161
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() func
5.3MEDIUM
CVE-2024-33155
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function
9.8CRITICAL
CVE-2024-33153
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function
9.8CRITICAL
CVE-2024-33149
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function
8.1HIGH
CVE-2024-33148
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.
7.3HIGH
CVE-2024-33147
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.
8.8HIGH
CVE-2024-33146
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
9.1CRITICAL
CVE-2024-33144
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage f
8.8HIGH
CVE-2024-33139
all versions
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
7.5HIGH
CVE-2023-2476
<= 2.6.0
A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown function
3.5LOW
CVE-2023-2475
<= 2.6.0
A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown processin
3.5LOW
CVE-2021-28890
all versions
J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId par
9.8CRITICAL
threatengine.sh