CVE-2021-37305
Insecure Permissions issue in jeecg-boot
Record summary
CVE-2021-37305 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 31, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
jeecgBrowse jeecg / jeecg | VulnCheck | Version data not supplied | |
org.jeecgframework.boot:jeecg-boot-baseBrowse Maven / org.jeecgframework.boot:jeecg-boot-base | GitHub Advisory | Through 2.4.5 | affected |
Nuclei templates
1ProjectDiscoveryHIGHJeecg Boot <= 2.4.5 - Sensitive Information DisclosureCVSS 7.5
Jeecg Boot <= 2.4.5 API interface has unauthorized access and leaks sensitive information such as email,phone and Enumerate usernames that exist in the system.
Impact
An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to unauthorized access or data leakage.
Remediation
Upgrade Jeecg Boot to version 2.4.6 or later to fix the vulnerability.
Source: ProjectDiscovery