Impact
JeecgBoot versions through 3.9.5 contain a missing authorization flaw in the AiOcrController updateById handler that lets any authenticated user send a PUT request to the /airag/ocr/edit endpoint to overwrite the shared LLM prompt stored in the airag:ocr Redis key. This can corrupt OCR results for all users, effectively allowing an attacker to tamper with application data and user experience. The weakness is a direct lack of permission checks for a protected resource, classified as CWE-862.
Affected Systems
The vulnerability affects the JeecgBoot application component known as JeecgBoot, specifically all releases up to and including 3.9.5. No other products or vendors are known to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, there is no published exploitation data. Attackers must be authenticated, but no higher privileges are required. The data can be modified by any user with basic access, providing a low-privileged vector for unauthorized changes.
OpenCVE Enrichment