Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14909

Опубликовано: 19 дек. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 8.1
CVSS2: 4
EPSS Низкий

Описание

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This patch is called b686f9fbd1917edffe5922c6362c817a9361cfbd. Applying a patch is advised to resolve this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*
Версия до 3.9.0 (включая)

EPSS

Процентиль: 25%
0.00087
Низкий

4.3 Medium

CVSS3

8.1 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-1018
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
около 2 месяцев назад

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This patch is called b686f9fbd1917edffe5922c6362c817a9361cfbd. Applying a patch is advised to resolve this issue.

EPSS

Процентиль: 25%
0.00087
Низкий

4.3 Medium

CVSS3

8.1 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-1018
NVD-CWE-noinfo