VYPR
Medium severity6.3NVD Advisory· Published Oct 1, 2025· Updated Jun 17, 2026

CVE-2025-61189

CVE-2025-61189

Description

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Jeecg/Jeecgboot3 versions
    cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*range: <=3.8.2
    • (no CPE)
    • (no CPE)range: <=3.8.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.