Impact
The vulnerability is an authorization bypass in OnlineController.getOnlineInfo of wxiaoqi Spring-Cloud-Platform. It allows remote actors to obtain user session or online information without proper authentication or authorization. This missing authorization weakness (CWE-862) and authorization bypass weakness (CWE-863) can expose potentially sensitive user data. Affected products include wxiaoqi Spring-Cloud-Platform releases 1.0, 2.2, and 3.0, where the vulnerable logic resides in aceModules/ace-admin/auth/controller/OnlineController.java. No patch has been released by the vendor, who has yet to respond to reported issues. The risk is moderate, with a CVSS score of 5.3 and an EPSS score of < 1%. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it remotely by sending a crafted request to the /online-info endpoint; a public proof‑of‑concept demonstrates this capability without requiring special credentials.
Affected Systems
Affected products are wxiaoqi Spring-Cloud-Platform releases 1.0, 2.2, and 3.0, which include the insecure OnlineController method in the aceModules/ace-admin/auth/controller package. Any deployment of these specific releases is vulnerable. There are no additional sub‑versions or hotfixes mentioned, and the project has not yet released a fix.
Risk and Exploitability
The vulnerability is moderately risky. With no EPSS score disclosed beyond the notation of < 1% and its absence from the CISA KEV catalog, the public exploit release indicates that attacker tools are available, but widespread targeting seems limited. An attacker can perform the exploit remotely by crafting a request to the vulnerable endpoint, and the GitHub proof‑of‑concept shows that no special environment is required. Administrators should treat this as a moderate threat that could let attackers gather additional user session information.
OpenCVE Enrichment