Impact
The vulnerability is located in the queryPageList method of SysUserController.java in JeecgBoot. By manipulating the salt argument, an attacker can obtain sensitive information that should not be publicly exposed. The flaw allows information disclosure with a high attack complexity. The vulnerability can be triggered remotely, but the attack is considered difficult to execute.
Affected Systems
JeecgBoot version 3.9.2 and earlier are affected. The issue is present in the User List Endpoint within the SysUserController component.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely, and while the exploit is publicly available, the complexity remains high and execution is difficult. The primary impact is the disclosure of protected data.
OpenCVE Enrichment