CVE-2025-15124
- EPSS 0.04%
- Veröffentlicht 28.12.2025 06:32:06
- Zuletzt bearbeitet 30.12.2025 19:05:30
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remot...
CVE-2025-15123
- EPSS 0.04%
- Veröffentlicht 28.12.2025 06:02:05
- Zuletzt bearbeitet 30.12.2025 19:05:39
A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The att...
CVE-2025-15122
- EPSS 0.04%
- Veröffentlicht 28.12.2025 05:16:05
- Zuletzt bearbeitet 30.12.2025 19:05:48
A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId results in improper authorization. It is possible ...
CVE-2025-15121
- EPSS 0.05%
- Veröffentlicht 28.12.2025 04:32:06
- Zuletzt bearbeitet 30.12.2025 19:06:19
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vend...
CVE-2025-15120
- EPSS 0.04%
- Veröffentlicht 28.12.2025 04:02:06
- Zuletzt bearbeitet 30.12.2025 19:07:13
A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be carried ou...
CVE-2025-15119
- EPSS 0.04%
- Veröffentlicht 28.12.2025 03:32:06
- Zuletzt bearbeitet 07.01.2026 21:35:31
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. ...
CVE-2025-14909
- EPSS 0.1%
- Veröffentlicht 19.12.2025 01:02:08
- Zuletzt bearbeitet 30.12.2025 18:31:31
A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineControlle...
CVE-2025-14908
- EPSS 0.27%
- Veröffentlicht 19.12.2025 00:32:08
- Zuletzt bearbeitet 30.12.2025 18:31:20
A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the co...
CVE-2025-61189
- EPSS 0.05%
- Veröffentlicht 01.10.2025 20:18:39
- Zuletzt bearbeitet 07.10.2025 14:42:52
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of...
CVE-2025-61188
- EPSS 0.05%
- Veröffentlicht 01.10.2025 20:18:38
- Zuletzt bearbeitet 07.10.2025 14:43:33
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified ...