Path Traversal Vulnerability in Jeecgboot by Jeecg
CVE-2025-61189

6.3MEDIUM

Key Information:

Vendor

Jeecg

Status
Vendor
CVE Published:
1 October 2025

What is CVE-2025-61189?

Jeecgboot versions up to 3.8.2 are vulnerable to a path traversal issue that can be exploited via the /sys/comment/addFile endpoint. This flaw permits malicious users to upload files with allowed extensions directly to the system directory /opt, circumventing the intended /opt/upFiles location specified by the web server. Such exploitation could lead to unauthorized access and manipulation of sensitive files within the system, jeopardizing the integrity and security of the server.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.