PT-2025-53641 · Unknown · Jeecg-Boot
Huangweigang
·
Published
2025-12-28
·
Updated
2025-12-28
·
CVE-2025-15126
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JeecgBoot versions up to 3.9.0
Description
A weakness exists in JeecgBoot related to improper authorization. The issue is triggered by manipulating the
positionId argument within the getPositionUserList function located in the /sys/position/getPositionUserList file. This manipulation can lead to unauthorized access. The attack can be initiated remotely, but is considered complex and difficult to exploit. The exploit has been publicly released. The vendor was notified but did not respond.Recommendations
Versions prior to 3.9.0 are affected.
Update JeecgBoot to a version newer than 3.9.0.
As a temporary workaround, restrict access to the
/sys/position/getPositionUserList file.Exploit
Fix
Incorrect Authorization
Incorrect Privilege Assignment
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecg-Boot