CVE-2025-15123: JeecgBoot datarule improper authorization
A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15123?
CVE-2025-15123 has a high severity rating due to the potential for improper authorization allowing unauthorized access to sensitive data.
How do I fix CVE-2025-15123?
To fix CVE-2025-15123, upgrade JeecgBoot to version 3.9.1 or later, as this version addresses the vulnerability.
What versions of JeecgBoot are affected by CVE-2025-15123?
CVE-2025-15123 affects JeecgBoot versions up to and including 3.9.0.
Can CVE-2025-15123 be exploited remotely?
Yes, CVE-2025-15123 can be exploited remotely, making it particularly dangerous.
What type of attacks are possible with CVE-2025-15123?
CVE-2025-15123 may allow attackers to perform unauthorized actions by manipulating access controls.