CVE-2025-10979: JeecgBoot exportXls improper authorization
A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10979?
CVE-2025-10979 is classified as a medium severity vulnerability due to its improper authorization issue.
How do I fix CVE-2025-10979?
To fix CVE-2025-10979, upgrade JeecgBoot to version 3.8.3 or later where this vulnerability has been addressed.
What products are affected by CVE-2025-10979?
CVE-2025-10979 affects JeecgBoot versions up to and including 3.8.2.
Is remote exploitation possible with CVE-2025-10979?
Yes, CVE-2025-10979 can be exploited remotely due to its design flaw.
What function in JeecgBoot is associated with CVE-2025-10979?
CVE-2025-10979 is related to an unknown function of the file /sys/role/exportXls.