Impact
The vulnerability arises from an omission of requiredPermission configuration for the /sysUser/detail and /sysUser/page endpoints in Guns 8.3.5. Authenticated users can bypass RBAC validation and retrieve complete user profiles, exposing usernames, real names, email addresses, phone numbers, last login IPs, and role assignments. This disclosure allows an attacker to gather sensitive information that could facilitate further attacks or profiling.
Affected Systems
The affected product is stylefeng Guns version 8.3.5. No other versions are explicitly listed, but the issue is tied to the code present in 8.3.5 and may exist in earlier releases lacking the permission check.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score is below 1%, suggesting that exploitation is unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Attackers require only a valid login token, allowing them to exploit the endpoint from any internal or possibly remote source where authentication is possible. No special privileges or code execution beyond reading data are required.
OpenCVE Enrichment