CVE-2021-37305 is an Insecure Permissions vulnerability (CWE-732) affecting jeecg-boot versions 2.4.5 and earlier. This flaw allows unauthenticated remote attackers to achieve escalated privileges and access sensitive information by exploiting a specific API endpoint (/sys/user/querySysUser?username=admin). Rated with a CVSSv3 score of 7.5 (High), it requires no user interaction or prior privileges, posing a significant risk to confidentiality. While not listed in CISA's Known Exploited Vulnerabilities catalog, exploit code, including Nuclei templates, is publicly available, and its high EPSS score (0.568) indicates a significant probability of exploitation, drawing active community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.5CPE matchmatch criteria | cpe:2.3:a:jeecg:jeecg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.