Assigner | mitre |
Reserved | 2023-01-23 |
Published | 2023-01-31 |
Updated | 2024-05-15 |
Description
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
References
https://gitee.com/dromara/hutool/issues/I6AJWJ#note_15801868
https://github.com/dromara/hutool/releases/tag/5.8.21
https://github.com/google/osv.dev/issues/2195
https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link
https://github.com/dromara/hutool/issues/3149