Impact
The vulnerability is a classic cross‑site scripting flaw within the upload component of JeecgBoot version 3.9.2. Through the /airag/chat/upload endpoint, an attacker can inject script payloads that are executed in the context of the victim’s browser, effectively allowing the attacker to run arbitrary code. This directly threatens confidentiality, integrity, and availability by enabling data theft, session hijacking, and further compromise of the application.
Affected Systems
Any deployment of JeecgBoot 3.9.2 that exposes the /airag/chat/upload endpoint is affected. No additional vendor or product information is available from a CNA source. Deployments running earlier or later releases are not known to be impacted.
Risk and Exploitability
The EPSS score is < 1% and the CVSS score of 6.1 indicates medium severity. The vulnerability is not listed in CISA KEV, indicating no public exploitation data yet. Based on the description, it is inferred that authentication is not required to reach the vulnerable endpoint, making the attack surface potentially wide. Because client‑side code can be injected and executed, the impact is high. Organizations should prioritize patching or blocking the endpoint, rather than merely monitoring for activity.
OpenCVE Enrichment