CVE-2025-10770

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
References
Link Resource
https://github.com/jeecgboot/jimureport/issues/4116 Exploit Issue Tracking Third Party Advisory
https://github.com/jeecgboot/jimureport/issues/4116#issue-3391107887 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.325126 Permissions Required VDB Entry
https://vuldb.com/?id.325126 Third Party Advisory VDB Entry
https://vuldb.com/?submit.649755 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeecg:jimureport:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-21 23:15

Updated : 2025-10-08 19:52


NVD link : CVE-2025-10770

Mitre link : CVE-2025-10770

CVE.ORG link : CVE-2025-10770


JSON object : View

Products Affected

jeecg

  • jimureport
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data