PT-2025-52399 · Unknown · Jeecg-Boot

Aibot88

·

Published

2025-12-19

·

Updated

2025-12-30

·

CVE-2025-14909

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions JeecgBoot versions prior to 3.9.0
Description A weakness exists in JeecgBoot that allows for the management of user sessions. The issue is located in the SysUserOnlineController function within the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. This manipulation can be performed remotely. The exploit for this issue has been publicly released.
Recommendations Apply patch b686f9fbd1917edffe5922c6362c817a9361cfbd to resolve this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14909

Affected Products

Jeecg-Boot