CVE-2025-10976

LOW

JeecgBoot < 3.8.2 - Improper Authorization via DepartId Parameter

Title source: llm
STIX 2.1

Description

A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing manipulation of the argument departId can lead to improper authorization. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.325847
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.325847
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.653333
Exploit, Third Party Advisory exploit
https://www.cnblogs.com/aibot/p/19063349

Scores

CVSS v3 3.1
EPSS 0.0034
EPSS Percentile 25.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (1)
jeecg/jeecg_boot < 3.8.2
Published Sep 25, 2025
Tracked Since Feb 18, 2026