漏洞描述 JeecgBoot是一款基于BPM的低代码平台。jeecg-boot <= 2.4.5版本中API 接口/sys/user/querySysUser存在泄露敏感信息,如电子邮件、电话、枚举系统中的用户名。攻击者通过构造特殊URL地址,读取系统敏感信息。
相关漏洞推荐 Jeecgboot /jmreport/save远程代码执行漏洞 无POC 2025-09-03 | Jeecgboot Jeecgboot 存在命令执行漏洞, 攻击者可以执行任意命令以获取服务器敏感信息以及权限。 CVE-2021-37304: Jeecg Boot <= 2.4.5 - Information Disclosure POC 2025-09-01 | Jeecg Boot An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain es... CVE-2021-37305: Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure POC 2025-09-01 | Jeecg Boot Jeecg Boot <= 2.4.5 API interface has unauthorized access and leaks sensitive information such as... ShowDoc /server/index.php?s=/api/adminUpdate/download 文件上传漏洞(CVE-2021-36440) 无POC 2025-09-12 | ShowDoc ShowDoc 2.9.5版本存在一个高危的文件上传漏洞(CVE-2021-36440),该漏洞源于系统未能对上传文件的类型进行充分验证。攻击者可以绕过安全限制上传任意类型的危险文件,包括但不限于PH... CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution POC 2025-09-01 | Cisco HyperFlex HX Data Platform Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that coul...