Impact
A flaw in the PreAuthorize handler within jeepay’s SysLogController allows an attacker to bypass authorization checks, enabling unauthorized reading of logging data. The vulnerability is triggered by manipulating the WebSecurityConfig endpoint, a modification that can be performed remotely. Once exploited, an attacker gains privileges it should not have, potentially exposing sensitive audit logs and internal state information, compromising confidentiality and the integrity of the logged events.
Affected Systems
The affected product is jeequan jeepay, versions up to 3.2.9 inclusive. No other vendors are listed; the CNA has identified a single component – the jeepay‑manager module in the sysuser package – as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium risk. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog; however, the description indicates that a publicly available exploit exists. Because the attack can be initiated remotely and the component is exposed via the web, the threat surface is high for systems that expose the SysLogController endpoint. The bypass is an authorization flaw (CWE-285, CWE-639) that does not require additional privileges beyond an authenticated session.
OpenCVE Enrichment