CVE-2025-14909
A weakness has been identified in JeecgBoot up to 3.9.0.
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This patch is called b686f9fbd1917edffe5922c6362c817a9361cfbd. Applying a patch is advised to resolve this issue.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1018
- Affected
- jeecg/jeecg boot
- Source
- cna@vuldb.com
References
- https://github.com/jeecgboot/JeecgBoot/commit/b686f9fbd1917edffe5922c6362c817a9361cfbdPatch
- https://github.com/jeecgboot/JeecgBoot/issues/9195Exploit, Issue Tracking, Third Party Advisory
- https://github.com/jeecgboot/JeecgBoot/issues/9195#issue-3719368751Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.337433Permissions Required, VDB Entry
- https://vuldb.com/?id.337433Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.715743Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.