Impact
JeecgBoot through version 3.9.5 contains an insecure direct object reference flaw that allows any authenticated user to retrieve the voice generation history of any other user. By supplying the target user’s ID in the GET /airag/voice/listByUser endpoint, an attacker can obtain the text‑to‑speech inputs, voice configuration, timestamps, and the names and paths of the generated audio files stored in Redis. This vulnerability is a classic IDOR problem (CWE‑639) and can expose sensitive personal data and usage patterns.
Affected Systems
The affected product is JeecgBoot, a Java-based framework used for building applications. The vulnerability exists in all installations using versions up to and including 3.9.5. No specific sub‑components beyond the /airag/voice module are listed, and vendor‑provided version ranges were not supplied.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the moderate severity range. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been publicly exploited at scale. The likely attack vector is authenticated, requiring the attacker to have a legitimate user account. Attackers can simply supply the victim’s user ID and trigger the endpoint, which no input validation is applied to, producing the sensitive data leak.
OpenCVE Enrichment