PT-2025-53641 · Unknown · Jeecg-Boot

Huangweigang

·

Published

2025-12-28

·

Updated

2025-12-28

·

CVE-2025-15126

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JeecgBoot versions up to 3.9.0
Description A weakness exists in JeecgBoot related to improper authorization. The issue is triggered by manipulating the positionId argument within the getPositionUserList function located in the /sys/position/getPositionUserList file. This manipulation can lead to unauthorized access. The attack can be initiated remotely, but is considered complex and difficult to exploit. The exploit has been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 3.9.0 are affected. Update JeecgBoot to a version newer than 3.9.0. As a temporary workaround, restrict access to the /sys/position/getPositionUserList file.

Exploit

Fix

Incorrect Authorization

Incorrect Privilege Assignment

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-15126

Affected Products

Jeecg-Boot