CVE-2025-51825

medium

Description

JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.

References

https://r4gd0ll.github.io/2025/JEECGBOOT_BYPASS_SQLInject.html

https://github.com/jeecgboot/JeecgBoot/issues/8335

Details

Source: Mitre, NVD

Published: 2025-08-22

Updated: 2025-10-01

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00031