Impact
JeecgBoot versions through 3.9.5 contain a missing authorization check that allows authenticated users with minimal privileges to create message templates via the POST /sys/message/sysMessageTemplate/add endpoint. By inserting templates with chosen codes and content, an attacker can populate the shared sys_sms_template library, potentially enabling unauthorized system, email, SMS, or instant message notifications.
Affected Systems
Users running JeecgBoot up to and including version 3.9.5 are at risk. The vulnerability was discovered in the SysMessageTemplateController within the system module and affects any deployment that has not yet applied the fix found in later releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Exploitation requires only an authenticated session and minimal role permissions; attackers can trigger the new templates by sending crafted POST requests to the exposed endpoint without additional privileges.
OpenCVE Enrichment