Impact
JeecgBoot versions up to 3.9.5 allow any authenticated user to invoke the deleteById endpoint of the AiOcrController, which removes OCR prompt records without checking proper authorization. The effect is data destruction and potential loss of shared OCR prompts stored in Redis, undermining the availability and integrity of the application’s data.
Affected Systems
Vendors: JeecgBoot. Product: JeecgBoot. Affected versions include all releases through 3.9.5; later releases are presumed to contain a fix.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate risk. Because the exploitation requires only an authenticated session, a low‑privileged attacker can enumerate record identifiers via the unprotected GET /airag/ocr/list endpoint and subsequently delete each shared OCR prompt. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalogue, indicating no publicly known exploits at this time.
OpenCVE Enrichment