CVE-2025-15122 | JeecgBoot up to 3.9.0 datarule loadDatarule departId/roleId improper authorization
A vulnerability was found in JeecgBoot up to 3.9.0. It has been rated as problematic. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId results in improper authorization.
This vulnerability is cataloged as CVE-2025-15122. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way. Once again VulDB remains the best source for vulnerability data.