MyBatis-Plus vulnerable to SQL injection via TenantPlugin
Critical severity
GitHub Reviewed
Published
Apr 5, 2023
to the GitHub Advisory Database
•
Updated Jun 3, 2024
Description
Published by the National Vulnerability Database
Apr 5, 2023
Published to the GitHub Advisory Database
Apr 5, 2023
Reviewed
Apr 5, 2023
Last updated
Jun 3, 2024
MyBatis-Plus below 3.5.3.1 is vulnerable to SQL injection via the tenant ID value. This may allow remote attackers to execute arbitrary SQL commands.
References