CVE-2025-10707: JeecgBoot sendMsg improper authorization
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10707?
CVE-2025-10707 is classified as a medium severity vulnerability due to its potential for improper authorization.
How do I fix CVE-2025-10707?
To remediate CVE-2025-10707, upgrade JeecgBoot to version 3.8.3 or later.
What kind of attacks can be executed using CVE-2025-10707?
CVE-2025-10707 can be exploited for remote unauthorized actions on affected systems.
Which versions of JeecgBoot are affected by CVE-2025-10707?
CVE-2025-10707 affects JeecgBoot versions up to and including 3.8.2.
What is the impact of exploiting CVE-2025-10707?
Exploiting CVE-2025-10707 can lead to unauthorized access to system messaging functionalities.