Impact
The flaw is a CWE-862 Authorization Bypass in SysNoticeController, where the requiredPermission defaults to false and is never changed by any method in the class. As a result, any authenticated user can create, edit, delete, publish, or retract system-wide notices, which can influence other users and departments within the system. This lack of proper access control exposes the application to misuse of its notification mechanism.
Affected Systems
The vulnerability affects the Stylefeng Guns framework, specifically version 8.3.5, and any deployments of this release that have not applied a later fix.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but possible. The issue is not yet listed in the CISA KEV catalog. An attacker would need to be authenticated, but without any role assignment, can exploit the privileged endpoints to alter notices across the organization. The exploit path requires web access to the SysNoticeController; it is inferred that the attacker logs in with a valid user account and then performs unauthorized operations via the exposed API endpoints.
OpenCVE Enrichment