Impact
JeecgBoot through version 3.9.5 contains a missing authorization flaw in the SysPositionController edit handler that lets any authenticated user alter position details such as names, codes, and ranks. The vulnerability is identified as a lack of access control (CWE-862) and enables low‑privileged attackers to modify organizational role information, potentially leading to privilege escalation or data integrity violations. The CVSS score of 5.3 reflects a moderate impact on confidentiality, integrity, and availability. The vulnerability is only exploitable by users who can authenticate to the system and does not require additional privileges beyond those granted to the attacker. The upstream code does not provide a unique SEI or remote vector, so the attack path requires the attacker to know or discover a valid session cookie or authentication token.
Affected Systems
All installations of JeecgBoot version 3.9.5 or earlier are affected. The vulnerability resides in the SysPositionController component responsible for editing organizational positions. Users of older versions who have not applied the latest release are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score is not available, so the probability of exploitation is unknown. The vulnerability is not currently listed in the CISA KEV catalog. Attackers need only authenticated access to the application; they can retrieve position identifiers from the unguarded list endpoint and then issue PUT or POST requests to /sys/position/edit. Given that the flaw is a missing authorization check, once an attacker can authenticate they can change any position record associated with the session. The exploitability is low to moderate because it requires active authentication and does not involve remote code execution or extensive exploitation steps.
OpenCVE Enrichment