Impact
JeecgBoot up to version 3.9.5 contains a missing authorization flaw in the AigcWordTemplateController deleteBatch endpoint. Attackers who are authenticated, even with limited privileges, can issue a DELETE request to /airag/word/deleteBatch, passing comma‑separated template identifiers, to permanently remove any word templates from the shared library. This results in irreversible data loss or disruption of downstream processes that rely on those templates and represents an unauthorized destruction capability. The weakness is categorized as CWE‑862 (Missing Authorization).
Affected Systems
The vulnerability affects the JeecgBoot application, specifically all releases through 3.9.5. Users running any 3.9.5 or earlier build are susceptible to the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the flaw is not listed in the CISA KEV catalog, suggesting limited evidence of exploitation in the wild. Attackers must be authenticated, but the low‑privilege requirement lowers the sophistication barrier. The vulnerability can be exploited by sending a crafted HTTP DELETE request to the specified endpoint, and the threat exists once an authenticated session is established.
OpenCVE Enrichment