CVE-2025-15120 | JeecgBoot up to 3.9.0 getDeptRoleList departId improper authorization (EUVD-2025-205493 / CNNVD-202512-4897)
A vulnerability was found in JeecgBoot up to 3.9.0. It has been classified as problematic. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization.
This vulnerability is tracked as CVE-2025-15120. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.