A vulnerability, which was classified as critical, was found in J2EEFAST 2.7.0. Affected is the function
myProcessList
. The manipulation of the argument sql_filter leads to sql injection.
This vulnerability is traded as CVE-2024-33149. It is possible to launch the attack remotely. There is no exploit available.