CVE-2025-15124 | JeecgBoot up to 3.9.0 list getParameterMap departId improper authorization (EUVD-2025-205496 / CNNVD-202512-4893)
A vulnerability identified as problematic has been detected in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization.
This vulnerability is documented as CVE-2025-15124. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.