PT-2025-37313 · Unknown · Jeecg-Boot
Aibot888
·
Published
2025-09-12
·
Updated
2025-09-12
·
CVE-2025-10318
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
JeecgBoot versions prior to 3.8.2
Description:
A vulnerability exists in JeecgBoot related to improper authorization within the WebSocket Message Handler component. The issue is associated with the
/api/system/sendWebSocketMsg API endpoint and the manipulation of the userIds parameter. This allows for remote exploitation. The vendor was contacted regarding this disclosure but did not respond. The exploit is publicly available.Recommendations:
Update JeecgBoot to a version later than 3.8.2.
Restrict access to the
/api/system/sendWebSocketMsg API endpoint.
Avoid using the userIds parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecg-Boot