Impact
JeecgBoot through version 3.9.5 contains a missing authorization flaw in the PUT /sys/dict/editDictByLowAppId endpoint, allowing any authenticated user to rename application dictionaries and replace their items. This flaw falls under CWE‑862 and permits attackers to alter configuration data, potentially compromising the integrity of low‑code applications and their data. The impact is limited to modified dictionary contents; it does not provide arbitrary code execution or full system compromise.
Affected Systems
The vulnerability affects JeecgBoot versions up to and including 3.9.5. No specific build numbers are listed beyond the major version, so any installation of JeecgBoot 3.9.5 or earlier is at risk. Upgrading to a later release that implements proper authorization for the /sys/dict/editDictByLowAppId endpoint eliminates the issue.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Attackers must first authenticate to the system, then retrieve a dictionary’s low_app_id via GET /sys/dict/list and supply it in the lowAppId parameter or X‑Low‑App‑ID header to the PUT endpoint. Because the attack requires valid authentication and only affects application configuration, the likelihood of exploitation is moderate to lower in environments with tight access controls.
OpenCVE Enrichment