CVE-2025-10980: JeecgBoot exportXls improper authorization
A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10980?
CVE-2025-10980 has been classified with a severity level that indicates a significant risk due to improper authorization vulnerabilities.
How do I fix CVE-2025-10980?
To fix CVE-2025-10980, upgrade JeecgBoot to version 3.8.3 or later, where the vulnerability is addressed.
What impact does CVE-2025-10980 have on affected systems?
CVE-2025-10980 can potentially allow remote attackers to exploit improper authorization to access restricted functionalities.
Which versions of JeecgBoot are affected by CVE-2025-10980?
CVE-2025-10980 affects all versions of JeecgBoot up to and including 3.8.2.
Is CVE-2025-10980 under active exploitation?
Yes, CVE-2025-10980 has been publicly disclosed and is considered to be under active exploitation.