CVE-2025-10770: jeecgboot JimuReport MySQL JDBC testConnection deserialization
A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10770?
The severity of CVE-2025-10770 is considered critical due to the potential for remote exploitation through deserialization attacks.
How do I fix CVE-2025-10770?
To fix CVE-2025-10770, upgrade jeecgboot JimuReport to version 2.1.3 or later where the vulnerability has been patched.
What kind of attacks can exploit CVE-2025-10770?
CVE-2025-10770 can be exploited through remote code execution due to deserialization vulnerabilities in the MySQL JDBC Handler.
Which versions of jeecgboot JimuReport are affected by CVE-2025-10770?
CVE-2025-10770 affects all versions of jeecgboot JimuReport up to and including version 2.1.2.
Is there a known exploit for CVE-2025-10770?
Yes, there are known exploits for CVE-2025-10770 that leverage the deserialization vulnerability for unauthorized access.