Impact
JeecgBoot through version 3.9.5 contains a missing authorization flaw in the SysUserController getUserDetailByUserId endpoint that allows any authenticated user to retrieve detailed information about any other user. The flaw permits exposure of real names, usernames, email addresses, phone numbers, birthdays, employee numbers, department paths and posts to low‑privileged attackers. This weakness is classed as CWE‑862 and results in a breach of confidentiality for user data.
Affected Systems
The vulnerability affects all installations of JeecgBoot up to and including version 3.9.5. The impacted component is the SysUserController within the JeecgBoot console. No specific build or environment constraints are documented, so any deployment of the affected version is susceptible unless patched.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium range. Since there is no EPSS score available and it is not listed in CISA KEV, the likelihood of exploitation today is uncertain but an authenticated user can execute the request without additional privilege escalation. The attack vector is thus an authenticated web request to /sys/user/getUserDetailByUserId; the flaw does not require any elevated privileges beyond valid credentials, making it a realistic threat for any user with access to the system.
OpenCVE Enrichment