Impact
The vulnerability resides in the SysMessageTemplateController delete handler and represents a Missing Authorization flaw, allowing any authenticated user to delete system message templates. By leveraging the unprotected list endpoint, attackers can discover template identifiers and delete shipped notification templates, which can cause system notices and workflow reminders to fail. The affected component is part of the JeecgBoot platform.
Affected Systems
JeecgBoot, version 3.9.5 and below are impacted. The flaw was discovered in the SysMessageTemplateController of the Jeecg module system.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated session; an attacker with login credentials or access to a legitimate account can exploit the endpoint. Successful exploitation could lead to denial of notification services within the application, potentially disrupting business processes.
OpenCVE Enrichment