CVE-2025-15124 is an improper authorization vulnerability affecting JeecgBoot up to version 3.9.0, specifically within the getParameterMap function of the /sys/sysDepartPermission/list file. This flaw allows a remote attacker to manipulate the 'departId' argument, potentially leading to unauthorized access to sensitive information. Despite a low CVSS score of 3.1, indicating low impact on confidentiality, the attack complexity is high, and exploitability is difficult. While a public exploit exists, there is currently no evidence of active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.9.0CPE matchmatch criteria | cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.