Impact
This vulnerability is an insecure direct object reference that permits an authenticated user to delete any other user's AI voice record by supplying a victim’s userId when calling DELETE /airag/voice/deleteVoiceRecord. The flaw relies on the CWE‑639 weakness, where the application fails to validate that the operating user is authorized to act on the specified object. When triggered, the deletion operates against Redis-stored text‑to‑speech entries, erasing a victim’s voice record history on every request. The impact is data loss and potential privacy violation, as the affected records may contain sensitive spoken content.
Affected Systems
JeecgBoot, version 3.9.5. The reported bug is present in all installations that have not applied a later patch and have authenticated users with privileges to call the DELETE endpoint. No other versions or installations were identified as affected in the available data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, reflecting that the vulnerability requires an authenticated user and is limited to data deletion. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting limited but non‑negligible exploitation potential. Attackers must authenticate, determine a target user’s ID (which can be obtained via the unsecured GET /airag/voice/listByUser endpoint), and craft a DELETE request bound to that ID. No elevated privileges or remote code execution are required; the risk is confined to unauthorized deletion of target user data.
OpenCVE Enrichment