CVE-2025-8963: jeecgboot JimuReport Data Large Screen Template testConnection deserialization
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8963?
CVE-2025-8963 is considered a critical vulnerability due to its potential for deserialization attacks.
How do I fix CVE-2025-8963?
To mitigate CVE-2025-8963, update jeecgboot JimuReport to version 2.1.2 or later.
What components are affected by CVE-2025-8963?
CVE-2025-8963 affects the Data Large Screen Template component of jeecgboot JimuReport version up to 2.1.1.
What type of vulnerability is CVE-2025-8963?
CVE-2025-8963 is a deserialization vulnerability that can lead to arbitrary code execution.
Can CVE-2025-8963 be exploited remotely?
Yes, CVE-2025-8963 can potentially be exploited remotely if the affected component is accessible.