PT-2025-37313 · Unknown · Jeecg-Boot

Aibot888

·

Published

2025-09-12

·

Updated

2025-09-12

·

CVE-2025-10318

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: JeecgBoot versions prior to 3.8.2
Description: A vulnerability exists in JeecgBoot related to improper authorization within the WebSocket Message Handler component. The issue is associated with the /api/system/sendWebSocketMsg API endpoint and the manipulation of the userIds parameter. This allows for remote exploitation. The vendor was contacted regarding this disclosure but did not respond. The exploit is publicly available.
Recommendations: Update JeecgBoot to a version later than 3.8.2. Restrict access to the /api/system/sendWebSocketMsg API endpoint. Avoid using the userIds parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10318

Affected Products

Jeecg-Boot