Impact
JeecgBoot versions up to and including 3.9.5 suffer from a missing authorization check in the SysDepartRoleController exportXls endpoint. The flaw allows any authenticated user to download all department role records, exposing role names, codes, descriptions, and the users who created them. This results in a moderate confidentiality breach, as non‑privileged users can gain insight into role structures and potentially identify target users for lateral movement.
Affected Systems
The vulnerability affects the JeecgBoot platform, specifically versions through 3.9.5. Authenticated accounts with even the default minimal role can trigger the export functionality. The affected endpoint is /sys/sysDepartRole/exportXls, which is part of the system module’s controller layer.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated user with valid credentials, which could be an insider or an external actor with compromised credentials. Exploitation requires only a valid session; no additional privileged context is needed. The lack of an authorization check means the attacker can obtain sensitive role data from any affected deployment.
OpenCVE Enrichment