Impact
Missing authorization in the AiragExtDataController exportXls endpoint allows any authenticated user to export all AI evaluator data and test-tracking records as an Excel file. An attacker who can authenticate to the system can therefore gain access to potentially sensitive user data, resulting in a confidentiality breach.
Affected Systems
JeecgBoot releases through version 3.9.5 are affected. The vulnerability resides in the AiragExtDataController component of the JeecgBoot module, impacting any deployment that has that module installed and permits user authentication.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a valid authenticated session, which can be provided by even low‑privileged users. Once authenticated, the attacker can make a direct request to /airag/extData/exportXls and receive the entire dataset in a single operation. The attack is straightforward and does not require additional privileges beyond login.
OpenCVE Enrichment