Opplus Springboot-Admin SQL Injection Vulnerability in SysLogDao.xml

Vulnerability

A critical SQL injection vulnerability has been identified in Opplus Springboot-Admin version 1.0. The issue arises from the 'order' argument being improperly handled in the SysLogDao.xml file, allowing for manipulation that leads to SQL injection. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can interfere with the application's database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Reproduction

The vulnerability can be reproduced by sending a request that includes a crafted 'order' parameter. This can be done by targeting the application endpoint that processes this parameter, which will trigger the SQL injection by manipulating the argument order.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.