Deserialization Vulnerability in jeecgboot JimuReport Affects MySQL JDBC Handler
CVE-2025-10770
Key Information:
- Vendor
Jeecgboot
- Status
- Vendor
- CVE Published:
- 21 September 2025
Badges
What is CVE-2025-10770?
A deserialization vulnerability has been identified in jeecgboot JimuReport, specifically affecting the MySQL JDBC Handler within the file /drag/onlDragDataSource/testConnection. This vulnerability allows an attacker to manipulate data, leading to the potential for remote code execution. As the exploit has been made publicly available, it poses significant risks if not addressed. Users of JimuReport up to version 2.1.2 are particularly urged to evaluate their systems and apply necessary security measures to mitigate this threat.
Affected Version(s)
JimuReport 2.1.0
JimuReport 2.1.1
JimuReport 2.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved