Impact
JeecgBoot up to version 3.9.5 contains a missing authorization flaw in the SysMessageController delete method. Authenticated users with low privileges can craft DELETE requests with arbitrary message IDs to remove any entry from the sys_sms table, erasing sent notification records without ownership checks and compromising data integrity and audit trail integrity.
Affected Systems
The vulnerability affects the JeecgBoot application. Any deployment of JeecgBoot up to and including version 3.9.5 that exposes the /sys/message/sysMessage/delete endpoint is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires an authenticated session; a low‑privileged user can delete arbitrary message records. The flaw does not allow remote code execution or privilege escalation, but it permits data loss and audit trail manipulation.
OpenCVE Enrichment