CVE-2023-24163

SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*

History

27 Mar 2025, 15:15

Type Values Removed Values Added
References (MISC) https://gitee.com/dromara/hutool/issues/I6AJWJ#note_15801868 - Exploit, Third Party Advisory () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_15801868 - Exploit, Third Party Advisory

21 May 2024, 17:23

Type Values Removed Values Added
References () https://github.com/google/osv.dev/issues/2195 - () https://github.com/google/osv.dev/issues/2195 - Issue Tracking
References () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link - () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link - Issue Tracking
References () https://github.com/dromara/hutool/issues/3149 - () https://github.com/dromara/hutool/issues/3149 - Issue Tracking
References () https://github.com/dromara/hutool/releases/tag/5.8.21 - () https://github.com/dromara/hutool/releases/tag/5.8.21 - Release Notes
CPE cpe:2.3:a:hutool:hutool:5.8.11:*:*:*:*:*:*:* cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*

15 May 2024, 16:15

Type Values Removed Values Added
References
  • () https://github.com/google/osv.dev/issues/2195 -
  • () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link -
  • () https://github.com/dromara/hutool/issues/3149 -
  • () https://github.com/dromara/hutool/releases/tag/5.8.21 -
Summary SQL Inection vulnerability in Dromara hutool v5.8.11 allows attacker to execute arbitrary code via the aviator template engine. SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.

Information

Published : 2023-01-31 16:15

Updated : 2025-05-16 20:23


NVD link : CVE-2023-24163

Mitre link : CVE-2023-24163


JSON object : View

Products Affected

hutool

  • hutool
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')