CVE-2025-15124: JeecgBoot list getParameterMap improper authorization
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15124?
CVE-2025-15124 has been classified as a medium severity vulnerability due to its potential for improper authorization.
How do I fix CVE-2025-15124?
To fix CVE-2025-15124, upgrade JeecgBoot to a version later than 3.9.0 to mitigate the unauthorized access issue.
What is the impact of CVE-2025-15124?
CVE-2025-15124 allows remote attackers to manipulate the departId parameter and gain unauthorized access to restricted functions.
Who is affected by CVE-2025-15124?
CVE-2025-15124 affects all users of JeecgBoot versions 3.9.0 and earlier.
Is CVE-2025-15124 remotely exploitable?
Yes, CVE-2025-15124 can be exploited remotely, making it critical for affected users to implement mitigation measures promptly.