Impact
A server-side request forgery vulnerability exists in JeecgBoot up to version 3.9.2. The flaw resides in an unknown function of the /airag/airagModel/test file, where an attacker can manipulate the baseUrl argument. This manipulation causes the application to send requests to arbitrary URLs on behalf of the server, potentially exposing internal resources. The CVSS score is 5.3.
Affected Systems
JeecgBoot applications built with or running versions up to 3.9.2 are affected. The specific affected element is a function within the /airag/airagModel/test file, but the vendor does not list more granular subcomponents.
Risk and Exploitability
The public exploit is available and the attack can be performed remotely. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the exploitation probability is uncertain but the presence of a public exploit raises concern. The vulnerability does not require local code execution or elevated privileges; it relies on remote manipulation of the baseUrl parameter and, if no network restrictions exist, the server can reach internal or external resources. The planned fix in the upcoming release indicates that the vendor is addressing the issue, but until that patch is applied, the risk remains moderate to high for organizations using affected versions.
OpenCVE Enrichment