CVE-2025-15124 | JeecgBoot up to 3.9.0 list getParameterMap departId improper authorization

Uncategorized

A vulnerability identified as problematic has been detected in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization.

This vulnerability is documented as CVE-2025-15124. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More