Impact
JeecgBoot through 3.9.5 contains a missing authorization flaw that permits any authenticated user with minimal privileges to change message templates via the PUT /sys/message/sysMessageTemplate/edit endpoint. By exploiting this, an attacker can obtain template identifiers from an unprotected list endpoint and overwrite system notification titles and content, injecting attacker‑supplied text or malicious links that will be presented to other users. The vulnerability does not give code execution but facilitates phishing or misinformation campaigns within the application.
Affected Systems
The affected product is JeecgBoot, versions up to and including 3.9.5. The patch fixes the issue in later releases, so all instances of JeecgBoot running 3.9.5 or older are vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 classifies the risk as moderate. No EPSS score is available, and the vulnerability is not listed in CISA KEV, implying limited known exploitation. The attack likely requires authentication but does not need elevated privileges, making it accessible to a wide range of users. An attacker can exploit the flaw by first retrieving a template ID from the list endpoint and then sending a crafted PUT request to alter the template, enabling the delivery of arbitrary content to other users.
OpenCVE Enrichment