PT-2026-47195 · Unknown · Jeecg-Boot
Rusty19
·
Published
2026-06-07
·
Updated
2026-06-07
·
CVE-2026-11464
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JeecgBoot versions prior to 3.9.3
Description
An information disclosure issue exists in the User List Endpoint. The manipulation of the
salt argument within the queryPageList() function of the srcmainjavaorgjeecgmodulessystemcontrollerSysUserController.java file allows for remote attacks. This issue is characterized by high complexity and difficult exploitation.Recommendations
Update to a version newer than 3.9.2.
As a temporary workaround, restrict access to the
queryPageList() function to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeecg-Boot