CVE-2025-12626 | jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd WxActGoldeneggsPrizesController.java getImgUrl imgurl path traversal (17/47 / EUVD-2025-37483)
A vulnerability marked as critical has been reported in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the argument imgurl results in path traversal.
This vulnerability is known as CVE-2025-12626. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.
The root cause was initially fixed but can be evaded with additional encoding.