CVE-2025-14909

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This patch is called b686f9fbd1917edffe5922c6362c817a9361cfbd. Applying a patch is advised to resolve this issue.
References
Link Resource
https://github.com/jeecgboot/JeecgBoot/commit/b686f9fbd1917edffe5922c6362c817a9361cfbd Patch
https://github.com/jeecgboot/JeecgBoot/issues/9195 Exploit Issue Tracking Third Party Advisory
https://github.com/jeecgboot/JeecgBoot/issues/9195#issue-3719368751 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.337433 Permissions Required VDB Entry
https://vuldb.com/?id.337433 Third Party Advisory VDB Entry
https://vuldb.com/?submit.715743 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-19 02:16

Updated : 2025-12-30 18:31


NVD link : CVE-2025-14909

Mitre link : CVE-2025-14909

CVE.ORG link : CVE-2025-14909


JSON object : View

Products Affected

jeecg

  • jeecg_boot
CWE
CWE-1018

Manage User Sessions

NVD-CWE-noinfo