CVE-2025-10707
- EPSS 0.05%
- Veröffentlicht 19.09.2025 11:32:10
- Zuletzt bearbeitet 31.12.2025 01:53:45
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has ...
CVE-2025-10319
- EPSS 0.04%
- Veröffentlicht 12.09.2025 15:15:32
- Zuletzt bearbeitet 31.12.2025 01:53:39
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack ca...
CVE-2025-10318
- EPSS 0.06%
- Veröffentlicht 12.09.2025 12:32:08
- Zuletzt bearbeitet 31.12.2025 01:53:33
A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to...
CVE-2025-51825
- EPSS 0.04%
- Veröffentlicht 22.08.2025 00:00:00
- Zuletzt bearbeitet 01.10.2025 20:22:23
JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.
CVE-2025-4533
- EPSS 0.67%
- Veröffentlicht 11.05.2025 06:31:04
- Zuletzt bearbeitet 31.12.2025 01:00:06
A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the a...
CVE-2024-48307
- EPSS 92.21%
- Veröffentlicht 31.10.2024 01:15:14
- Zuletzt bearbeitet 27.06.2025 19:45:28
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
CVE-2023-34602
- EPSS 0.44%
- Veröffentlicht 19.06.2023 06:15:09
- Zuletzt bearbeitet 12.12.2024 01:23:46
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.
CVE-2023-34603
- EPSS 0.32%
- Veröffentlicht 19.06.2023 06:15:09
- Zuletzt bearbeitet 12.12.2024 01:23:46
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.