First published: Fri Feb 03 2023(Updated: )
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jeecg Jeecg | <=2.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37306 is an insecure permissions issue in jeecg-boot 2.4.5 and earlier that allows remote attackers to gain escalated privilege and view sensitive information.
Remote attackers can exploit CVE-2021-37306 by sending a specially crafted request to the API uri '/sys/user/checkOnlyUser?username=admin', which allows them to gain escalated privilege and view sensitive information.
CVE-2021-37306 has a severity of high with a CVSS (Common Vulnerability Scoring System) score of 7.5.
jeecg-boot version 2.4.5 and earlier are affected by CVE-2021-37306.
Yes, the fix for CVE-2021-37306 is available in newer versions of jeecg-boot. It is recommended to update to the latest version to mitigate the vulnerability.