PT-2026-21430 · Unknown · Jeecg-Boot

Saul1213

·

Published

2026-02-22

·

Updated

2026-03-03

·

CVE-2026-2945

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JeecgBoot version 3.9.0
Description A server-side request forgery condition exists in JeecgBoot 3.9.0. This issue is related to the file /sys/common/uploadImgByHttp. Manipulation of the fileUrl argument can lead to server-side request forgery. The attack can be initiated remotely. The exploit has been publicly released. The vendor was notified but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-2945

Affected Products

Jeecg-Boot