CVE-2025-15121
- EPSS 0.05%
- Veröffentlicht 28.12.2025 04:32:06
- Zuletzt bearbeitet 30.12.2025 19:06:19
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vend...
CVE-2025-15120
- EPSS 0.04%
- Veröffentlicht 28.12.2025 04:02:06
- Zuletzt bearbeitet 30.12.2025 19:07:13
A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be carried ou...
CVE-2025-15119
- EPSS 0.04%
- Veröffentlicht 28.12.2025 03:32:06
- Zuletzt bearbeitet 07.01.2026 21:35:31
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. ...
CVE-2025-14909
- EPSS 0.1%
- Veröffentlicht 19.12.2025 01:02:08
- Zuletzt bearbeitet 30.12.2025 18:31:31
A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineControlle...
CVE-2025-14908
- EPSS 0.27%
- Veröffentlicht 19.12.2025 00:32:08
- Zuletzt bearbeitet 30.12.2025 18:31:20
A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the co...
CVE-2025-61189
- EPSS 0.05%
- Veröffentlicht 01.10.2025 20:18:39
- Zuletzt bearbeitet 07.10.2025 14:42:52
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of...
CVE-2025-61188
- EPSS 0.05%
- Veröffentlicht 01.10.2025 20:18:38
- Zuletzt bearbeitet 07.10.2025 14:43:33
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified ...
CVE-2025-10707
- EPSS 0.05%
- Veröffentlicht 19.09.2025 11:32:10
- Zuletzt bearbeitet 31.12.2025 01:53:45
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has ...
CVE-2025-10319
- EPSS 0.03%
- Veröffentlicht 12.09.2025 15:15:32
- Zuletzt bearbeitet 31.12.2025 01:53:39
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack ca...
CVE-2025-10318
- EPSS 0.05%
- Veröffentlicht 12.09.2025 12:32:08
- Zuletzt bearbeitet 31.12.2025 01:53:33
A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to...