Impact
This vulnerability arises from a missing authorization check in the SysPositionController deleteBatch endpoint. The flaw permits any authenticated user to submit batch deletion requests for organizational positions, using comma‑separated IDs obtained from an unprotected list endpoint. As a result, attackers can delete position records and orphan user‑position relationships, disrupting role assignments and compromising system integrity.
Affected Systems
JeecgBoot versions up to and including 3.9.5 are affected. The issue resides in the SysPositionController component of the JeecgBoot framework, which is used by deployments that expose the /sys/position/deleteBatch API endpoint.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. With no EPSS data available, the exploitation probability is uncertain, but the vulnerability is easy to exploit as it only requires authentication and no special privileges. The attack vector is through the application layer, targeting authenticated users. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet.
OpenCVE Enrichment