CVE-2023-39016: Bbossgroups Bboss
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.
Affected products
- Bbossgroups Bboss: up to and including 6.0.9
Published 2023-07-28. Last modified 2026-06-17.