Impact
JeecgBoot versions up to 3.9.5 expose a missing authorization flaw in the AiragExtDataController delete handler. The flaw allows users who are authenticated but do not have proper privileges to issue DELETE requests to /airag/extData/delete with any identifier and remove other users’ AI evaluator or test‑tracking records. The impact is the loss or tampering of data that belongs to other users, effectively degrading the integrity and availability of the system’s AI evaluation component but not directly exposing confidential data.
Affected Systems
The vulnerability affects JeecgBoot products released through version 3.9.5. The affected controller is AiragExtDataController in the JeecgBoot module Airag. Any installations deploying these versions without the fix are susceptible.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as moderate severity. The EPSS score is not available, indicating insufficient data to gauge exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Attackers require only an authenticated session with low privileges, meaning the vulnerability can be exploited remotely via the web interface by any user who can log into the application.
OpenCVE Enrichment