PT-2025-38668 · Unknown · Jeecgboot Jimureport
Ez-Lbz
·
Published
2025-09-21
·
Updated
2026-01-09
·
CVE-2025-10770
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
jeecgboot JimuReport versions up to 2.1.2
Description
A vulnerability exists in jeecgboot JimuReport up to version 2.1.2. The issue impacts an unknown function within the
/drag/onlDragDataSource/testConnection file of the MySQL JDBC Handler component, leading to deserialization. Remote exploitation is possible. The exploit has been made public.Recommendations
Versions prior to 2.1.2 should be used.
Consider restricting access to the
/drag/onlDragDataSource/testConnection file as a temporary workaround.Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecgboot Jimureport