PT-2026-47195 · Unknown · Jeecg-Boot

Rusty19

·

Published

2026-06-07

·

Updated

2026-06-07

·

CVE-2026-11464

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions JeecgBoot versions prior to 3.9.3
Description An information disclosure issue exists in the User List Endpoint. The manipulation of the salt argument within the queryPageList() function of the srcmainjavaorgjeecgmodulessystemcontrollerSysUserController.java file allows for remote attacks. This issue is characterized by high complexity and difficult exploitation.
Recommendations Update to a version newer than 3.9.2. As a temporary workaround, restrict access to the queryPageList() function to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-11464

Affected Products

Jeecg-Boot