CVE-2025-4533 Information
Description
A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the argument File leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Reference
https://github.com/jeecgboot/JeecgBoot/issues/8199 https://github.com/jeecgboot/JeecgBoot/issues/8199#issue-3022937633 https://github.com/jeecgboot/JeecgBoot/issues/8199#issuecomment-2834691016 https://vuldb.com/?ctiid.308278 https://vuldb.com/?id.308278 https://vuldb.com/?submit.566192
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
2.7
Share on: