CVE-2025-51825

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
22/08/2025
Last modified:
01/10/2025

Description

JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:guojusoft:jeecgboot:*:*:*:*:*:*:*:* 3.4.3 (including) 3.8.0 (including)