S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-37305 Scanner

CVE-2021-37305 scanner - Sensitive Information Disclosure vulnerability in Jeecg Boot

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-37305
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Jeecg Boot is a high-performance, low-code development platform that accelerates the creation and deployment of web and mobile applications. It is designed for enterprise-level use, facilitating rapid development with minimal coding. This platform is widely adopted for its efficiency in developing complex applications, offering a suite of tools for managing databases, business logic, and user interfaces. However, vulnerabilities within such platforms can lead to significant security risks, including unauthorized access and data exposure.

The vulnerability is attributed to inadequate access controls on specific API endpoints, allowing unauthenticated requests to retrieve sensitive user information. An attacker can exploit this by crafting a simple HTTP GET request targeting the vulnerable endpoint, resulting in the exposure of sensitive details without requiring authentication or user interaction.

The exploitation of this vulnerability can lead to significant privacy breaches, with attackers gaining access to personal information that could be used for phishing attacks, identity theft, or further unauthorized access to the system. This compromises the integrity of the platform and the security of user data, potentially leading to loss of trust and reputational damage.

S4E platform offers an advanced scanning solution that identifies vulnerabilities like CVE-2021-37305, providing users with the necessary insights and recommendations to secure their digital infrastructure. By utilizing our platform, organizations can ensure the security and integrity of their applications, safeguarding against data breaches and enhancing their cybersecurity posture.

 

References

Solution Advice
  1. Promptly upgrade to Jeecg Boot version 2.4.6 or later to address this vulnerability.
  2. Review and strengthen access controls on all API endpoints, ensuring that sensitive information is only accessible to authenticated and authorized users.
  3. Conduct a comprehensive security audit of the application to identify and remediate potential vulnerabilities.
  4. Implement regular security training for development and operations teams to reinforce best practices in secure coding and application security.
  5. Engage in continuous monitoring and testing of the application's security measures to detect and respond to new vulnerabilities promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.