PT-2026-47264 · Unknown · Jeecg-Boot
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JeecgBoot versions prior to 3.9.3
Description
An open redirect issue exists in the Third-Party Login component. The
HttpServletResponse.sendRedirect() function within the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java does not properly validate the state argument, allowing remote attackers to redirect users to arbitrary external sites. Exploitation requires social engineering to induce a victim to click a specially crafted OAuth login link. This feature is optional and may not be enabled in all installations.Recommendations
Update to a version later than 3.9.2.
As a temporary mitigation, disable the Third-Party Login feature if it is not required for the project's operations.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jeecg-Boot