CVE-2025-51825: SQL Injection
Published Aug 22, 2025
·Updated
JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.
Affected Software
3 affected componentsFixes available
JeecgBoot JeecgBoot>=3.4.3, <=3.8.0
maven/org.jeecgframework.boot:jeecg-boot-base-core>=3.4.3<3.8.1
3.8.1
Guojusoft Jeecgboot>=3.4.3<=3.8.0
Event History
Aug 22, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
Affected Software
Advisory Published
via GitHub·03:33 PM
Data Sourced
via GitHub·03:33 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51825?
CVE-2025-51825 has been classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2025-51825?
To fix CVE-2025-51825, upgrade JeecgBoot to version 3.8.1 or later.
3
What is the impact of CVE-2025-51825?
CVE-2025-51825 allows attackers to bypass SQL blacklist restrictions, potentially leading to unauthorized data access.
4
Which versions of JeecgBoot are affected by CVE-2025-51825?
JeecgBoot versions from 3.4.3 up to 3.8.0 are affected by CVE-2025-51825.
5
Where can I find more information about CVE-2025-51825?
Further details about CVE-2025-51825 can be found in the JeecgBoot issue tracker on GitHub.