CVE-2025-15119: JeecgBoot list queryPageList improper authorization
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15119?
CVE-2025-15119 is considered a high severity vulnerability due to its potential for remote exploitation and improper authorization.
How do I fix CVE-2025-15119?
To remediate CVE-2025-15119, upgrade JeecgBoot to version 3.9.1 or later where the vulnerability has been patched.
Which versions of JeecgBoot are affected by CVE-2025-15119?
CVE-2025-15119 affects JeecgBoot versions up to and including 3.9.0.
What type of vulnerability is CVE-2025-15119?
CVE-2025-15119 is categorized as an authorization vulnerability that allows improper access control.
Can CVE-2025-15119 be exploited remotely?
Yes, CVE-2025-15119 can be exploited remotely, making it a significant security concern.