PT-2025-53641 · Unknown · Jeecg-Boot

·

CVE-2025-15126

·

Published

2025-12-28

·

Updated

2025-12-28

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JeecgBoot versions up to 3.9.0
Description A weakness exists in JeecgBoot related to improper authorization. The issue is triggered by manipulating the positionId argument within the getPositionUserList function located in the /sys/position/getPositionUserList file. This manipulation can lead to unauthorized access. The attack can be initiated remotely, but is considered complex and difficult to exploit. The exploit has been publicly released. The vendor was notified but did not respond.
Recommendations Versions prior to 3.9.0 are affected. Update JeecgBoot to a version newer than 3.9.0. As a temporary workaround, restrict access to the /sys/position/getPositionUserList file.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15126

Affected Products

Jeecg-Boot