Impact
JeecgBoot implements a deleteBatch endpoint for system audit logs that performs no authorization checks. As a result, any user who has successfully authenticated to the application can send a DELETE request and remove log entries. Low‑privileged attackers can pass the parameter 'ids=allclear' to delete every row in the sys_log table, wiping the audit trail and making post‑incident investigation difficult. This weakness is a classic case of Missing Authorization (CWE‑862).
Affected Systems
Affected product is JeecgBoot, version 3.9.5 and earlier. The issue exists in the SysLogController component that handles system log deletion. The vendors are JeecgBoot; the exact version number for the fix is not provided, but any release beyond 3.9.5 that implements proper authorization should be used.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. Because the exploitation requires only an authenticated session, users with low privileges can trigger the delete at will. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, yet the potential for evidence tampering makes it a significant risk in regulated or forensic environments.
OpenCVE Enrichment