CVE-2025-15121
- EPSS 0.05%
- Veröffentlicht 28.12.2025 04:32:06
- Zuletzt bearbeitet 30.12.2025 19:06:19
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vend...
CVE-2025-15120
- EPSS 0.04%
- Veröffentlicht 28.12.2025 04:02:06
- Zuletzt bearbeitet 30.12.2025 19:07:13
A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be carried ou...
CVE-2025-15119
- EPSS 0.04%
- Veröffentlicht 28.12.2025 03:32:06
- Zuletzt bearbeitet 07.01.2026 21:35:31
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. ...
CVE-2025-14909
- EPSS 0.1%
- Veröffentlicht 19.12.2025 01:02:08
- Zuletzt bearbeitet 30.12.2025 18:31:31
A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineControlle...
CVE-2025-14908
- EPSS 0.27%
- Veröffentlicht 19.12.2025 00:32:08
- Zuletzt bearbeitet 30.12.2025 18:31:20
A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the co...
CVE-2025-61189
- EPSS 0.05%
- Veröffentlicht 01.10.2025 20:18:39
- Zuletzt bearbeitet 07.10.2025 14:42:52
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of...
CVE-2025-61188
- EPSS 0.05%
- Veröffentlicht 01.10.2025 20:18:38
- Zuletzt bearbeitet 07.10.2025 14:43:33
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified ...
CVE-2025-10981
- EPSS 0.03%
- Veröffentlicht 26.09.2025 00:15:37
- Zuletzt bearbeitet 31.12.2025 00:59:45
A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and ...
CVE-2025-10980
- EPSS 0.03%
- Veröffentlicht 26.09.2025 00:15:36
- Zuletzt bearbeitet 31.12.2025 00:59:32
A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit ha...
CVE-2025-10979
- EPSS 0.03%
- Veröffentlicht 25.09.2025 23:15:48
- Zuletzt bearbeitet 31.12.2025 01:54:28
A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper authorization. It is possible to initiate the attack remotely. The exploit has bee...