CVE-2025-15121: JeecgBoot getDeptRoleByUserId information disclosure
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15121?
CVE-2025-15121 is classified as a medium-severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2025-15121?
To mitigate CVE-2025-15121, upgrade JeecgBoot to version 3.9.1 or later where the vulnerability has been addressed.
What type of vulnerability is CVE-2025-15121?
CVE-2025-15121 is an information disclosure vulnerability affecting the getDeptRoleByUserId function in JeecgBoot.
Which versions of JeecgBoot are affected by CVE-2025-15121?
CVE-2025-15121 affects all versions of JeecgBoot up to and including 3.9.0.
Is there a workaround for CVE-2025-15121?
As a temporary workaround for CVE-2025-15121, restrict access to the affected function until the software is updated.