Impact
SmartAdmin API for Java17 SpringBoot3 version 3.30.0 contains an improper authorization flaw on the /employee/queryAll endpoint. The endpoint fails to enforce the required function‑level permission or data‑scope checks, enabling an authenticated low‑privileged employee to retrieve records belonging to other departments and users. This weakness results in unauthorized disclosure of personnel data and violates confidentiality, classifying the issue as an access‑control bypass (CWE‑862). Based on the description, it is inferred that only authenticated users may exploit the flaw and that the attack vector is internal.
Affected Systems
Affected systems include the SmartAdmin API built on Java17 SpringBoot3, version 3.30.0. No other vendors or product versions are reported in the CVE data. The vulnerability resides solely in the /employee/queryAll endpoint.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of < 1 % reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in KEV. Exploitation requires authentication and is likely to occur in an internal or local context. The flaw permits the exfiltration of employee data across departments, underscoring a significant risk to confidentiality for sensitive workforce information.
OpenCVE Enrichment