CVE-2025-8527 | Exrick xboot up to 3.3.4 Swagger SecurityController.java loginUrl server-side request forgery
A vulnerability described as critical has been identified in Exrick xboot up to 3.3.4. This issue affects some unknown processing of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/SecurityController.java of the component Swagger. Executing manipulation of the argument loginUrl can lead to server-side request forgery.
This vulnerability is tracked as CVE-2025-8527. The attack can be launched remotely. Moreover, an exploit is present.