Impact
The vulnerability is a missing authorization flaw in the SysPositionController removeUserPosition handler of JeecgBoot up to version 3.9.5. Any authenticated user can send a DELETE request to /sys/position/removePositionUser with arbitrary userIds and positionId values, which causes the application to delete rows in the sys_user_position table. This detaches users from their assigned positions without logging the action, potentially disrupting role‑based access for legitimate users.
Affected Systems
JeecgBoot versions 3.9.5 and earlier, as the flaw exists in the SysPositionController component of the JeecgBoot application.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an authenticated web request; any authenticated user can exploit the flaw by sending a DELETE request with crafted userIds and positionId values. Successful exploitation leads to unauthorized removal of user roles, which can impact availability of privileged actions for the affected users.
OpenCVE Enrichment