Impact
JeecgBoot versions up to 3.9.5 contain a missing authorization check in the AigcWordTemplateController edit handler, allowing any authenticated user to perform PUT or POST requests to /airag/word/edit. This flaw enables the attacker to overwrite shared word templates that other users rely on for document generation, potentially causing misinformation, regulatory non‑compliance, or denial of service. It is a classic Missing Authorization weakness (CWE-862).
Affected Systems
The affected software is JeecgBoot, all releases up to and including version 3.9.5. No specific sub‑module version constraints are listed, but any instance of the product exposing the /airag/word/edit endpoint is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and no EPSS data is available. It is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to possess valid authentication credentials within the application, after which a simple HTTP request to the vulnerable endpoint can modify templates. The attack path is straightforward and does not require local system access or privilege escalation.
OpenCVE Enrichment