PT-2025-34368 · Unknown · Jeecg-Boot

R4Gd0Ll

·

Published

2025-08-22

·

Updated

2025-08-22

·

CVE-2025-51825

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: JeecgBoot versions 3.4.3 through 3.8.0
Description: JeecgBoot versions 3.4.3 through 3.8.0 contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint. This vulnerability allows bypassing SQL blacklist restrictions.
Recommendations: Update JeecgBoot to a version later than 3.8.0.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-51825
GHSA-GJ8W-FFQ9-6828

Affected Products

Jeecg-Boot