CVE-2025-10770

MEDIUM

jeecg/jimureport < 2.1.2 - Deserialization via MySQL JDBC Handler

Title source: llm
STIX 2.1

Description

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.325126
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.325126
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.649755
Exploit, Issue Tracking, Third Party Advisory issue-tracking
https://github.com/jeecgboot/jimureport/issues/4116
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/jeecgboot/jimureport/issues/4116#issue-3391107887

Scores

CVSS v3 6.3
EPSS 0.0040
EPSS Percentile 31.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-502
Status published
Products (1)
jeecg/jimureport < 2.1.2
Published Sep 21, 2025
Tracked Since Feb 18, 2026