Record summary

CVE-2021-37305 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 31, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

org.jeecgframework.boot:jeecg-boot-base

Browse Maven / org.jeecgframework.boot:jeecg-boot-base
GitHub AdvisoryThrough 2.4.5affected

Nuclei templates

1
ProjectDiscoveryHIGHJeecg Boot <= 2.4.5 - Sensitive Information DisclosureCVSS 7.5

Jeecg Boot <= 2.4.5 API interface has unauthorized access and leaks sensitive information such as email,phone and Enumerate usernames that exist in the system.

Impact

An attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to unauthorized access or data leakage.

Remediation

Upgrade Jeecg Boot to version 2.4.6 or later to fix the vulnerability.

WeaknessesCWE-732
Authorsritikchaddha
Template tagscve2021cvejeecgexposurevulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:jeecg:jeecg:*:*:*:*:*:*:*:*
Shodan: title:"Jeecg-Boot"
Shodan: http.title:"jeecg-boot"
FOFA: title="JeecgBoot 企业级低代码平台"
FOFA: title="jeecg-boot"
FOFA: title="jeecgboot 企业级低代码平台"
Google: intitle:"jeecg-boot"

Source: ProjectDiscovery

References

3