SQL Injection Vulnerability in JeecgBoot by Jeecg
CVE-2025-51825
6.5MEDIUM
What is CVE-2025-51825?
JeecgBoot versions ranging from 3.4.3 to 3.8.0 are subject to a SQL injection vulnerability discovered in the endpoint /jeecg-boot/online/cgreport/head/parseSql. This flaw permits attackers to circumvent SQL blacklist restrictions, potentially leading to unauthorized access to sensitive data and database manipulation. Security measures should be implemented to mitigate the risks posed by this vulnerability.