Exrick xboot Swagger SecurityController.java server-side request forgery

CVE Details

Basic Information

Title Exrick xboot Swagger SecurityController.java server-side request forgery
Type cve
Published 2025-08-04T21:32:06.008Z
Modified 2025-08-04T21:32:06.008Z

Product Information

Vendor Exrick
Product xboot
Version 3.3.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A server-side request forgery vulnerability in Exrick xboot’s Swagger component allows remote attackers to make unauthorized requests, potentially exposing internal resources or enabling further attacks.
AI Severity Medium
AI Vendor Exrick
AI Product xboot
AI Version 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4

Affected Products

  • Exrick xboot 3.3.0
  • Exrick xboot 3.3.1
  • Exrick xboot 3.3.2
  • Exrick xboot 3.3.3
  • Exrick xboot 3.3.4

Additional Information

CWE List CWE-918
Source VulDB

Description

A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/SecurityController.java of the component Swagger. The manipulation of the argument loginUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.