CVE-2025-10770

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
References
Link Resource
https://github.com/jeecgboot/jimureport/issues/4116 Exploit Issue Tracking Third Party Advisory
https://github.com/jeecgboot/jimureport/issues/4116#issue-3391107887 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.325126 Permissions Required VDB Entry
https://vuldb.com/?id.325126 Third Party Advisory VDB Entry
https://vuldb.com/?submit.649755 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeecg:jimureport:*:*:*:*:*:*:*:*

History

08 Oct 2025, 19:52

Type Values Removed Values Added
CPE cpe:2.3:a:jeecg:jimureport:*:*:*:*:*:*:*:*
First Time Jeecg jimureport
Jeecg
References () https://github.com/jeecgboot/jimureport/issues/4116 - () https://github.com/jeecgboot/jimureport/issues/4116 - Exploit, Issue Tracking, Third Party Advisory
References () https://github.com/jeecgboot/jimureport/issues/4116#issue-3391107887 - () https://github.com/jeecgboot/jimureport/issues/4116#issue-3391107887 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.325126 - () https://vuldb.com/?ctiid.325126 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.325126 - () https://vuldb.com/?id.325126 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.649755 - () https://vuldb.com/?submit.649755 - Third Party Advisory, VDB Entry

21 Sep 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-21 23:15

Updated : 2025-10-08 19:52


NVD link : CVE-2025-10770

Mitre link : CVE-2025-10770

CVE.ORG link : CVE-2025-10770


JSON object : View

Products Affected

jeecg

  • jimureport
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data