Impact
A flaw in the anonymous chat attachment parser of JeecgBoot allows a remote attacker to manipulate the /airag/chat/send endpoint so the server performs arbitrary HTTP requests to external resources, a classic server‑side request forgery. The weakness does not require local privileges and is described as CWE‑918. The exploit is available publicly and can be used to exfiltrate data, conduct further attacks, or impact other systems through that request capability.
Affected Systems
JeecgBoot applications up to version 3.9.2 are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS information is not available, so the likelihood of exploitation is uncertain, but the vulnerability is publicly referenced and may be used in practice. It is not included in the CISA KEV catalog. Attackers can instantiate the vulnerability via remote calls to the exposed chat endpoint, inferring that no authentication is required to trigger the request forgery.
OpenCVE Enrichment