guns
guns copied to clipboard
guns Vulnerability Alerts
guns Vulnerability Alerts
Dear Developer,
We have identified multiple SQL injection vulnerabilities and file operation vulnerabilities in Guns. The specific function call stacks are provided below. Please address these issues as soon as possible. The primary cause of the SQL injection vulnerabilities is the lack of filtering for $
content in MyBatis' Mapper.xml.
Best regards,
==============================
[1] Found sink method:
<com.stylefeng.guns.common.
(1) Found vul call chain:
<com.stylefeng.guns.modular.
<com.stylefeng.guns.common.
==============================
[2] Found sink method:
<java.io.File: void <init>(java.lang.String)>
(1) Found vul call chain:
<com.stylefeng.guns.modular.
<com.stylefeng.guns.core.util.
<java.io.File: void <init>(java.lang.String)>
==============================
[3] Found sink method:
<com.stylefeng.guns.common.
(1) Found vul call chain:
<com.stylefeng.guns.modular.
<com.stylefeng.guns.common.