Impact
A DELETE /airag/video/deleteVideoRecord endpoint in JeecgBoot 3.9.5 lacks validation that the supplied userId matches the authenticated user, enabling an authenticated attacker to delete video generation records belonging to any user ID they specify. By retrieving record identifiers from the unfiltered GET /airag/video/listByUser endpoint, an attacker can systematically erase victims’ Redis‑stored video history entries, erasing user data without affecting other system components.
Affected Systems
All installations of JeecgBoot up through version 3.9.5 are susceptible, as the vulnerability resides in the jeecg-boot module that handles AI video generation. Any instance exposing the DELETE endpoint to authenticated users is at risk.
Risk and Exploitability
The CVSS score of 5.3 classifies this issue as moderate severity, and the EPSS score is not available; it is not listed in the CISA KEV catalog. Exploitation requires valid user credentials, meaning only attackers who have gained legitimate access to the system can perform the deletion. While the vulnerability does not allow arbitrary code execution or denial of service, repeated use could cause significant data loss for affected users.
OpenCVE Enrichment