216.73.216.6

CVE-2026-11464

· Published 07/06/2026 23:16 · Modified 08/06/2026 14:57

Labels: CVE-2026-11464 2026-06-07CVE-2026-11464CWE-200[email protected]

Essential information

Published
07/06/2026 23:16
Modified
08/06/2026 14:57
Author
Creator
CVSS
1.3 LOW (v3) 1.3 LOW (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt leads to information disclosure. The attack may be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is publicly available and might be used. A fix is planned for the upcoming release.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
jeecg / jeecgboot cpe:2.3:a:jeecg:jeecgboot:*:*:*:*:*:*:*:*

References