5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/SecurityController.java of the component Swagger. The manipulation of the argument loginUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Basic Information
ID
CVE-2025-8527
Source
VulDB
Published
Aug 4, 2025 at 21:32
Modified
Aug 5, 2025 at 13:38
Affected Product
Vendor
Exrick
Product
xboot
Version
3.3.0
Affected Versions
Exrick xboot 3.3.0
Exrick xboot 3.3.1
Exrick xboot 3.3.2
Exrick xboot 3.3.3
Exrick xboot 3.3.4
Exrick xboot 3.3.1
Exrick xboot 3.3.2
Exrick xboot 3.3.3
Exrick xboot 3.3.4