Impact
A flaw in the usernameExist method of the UserController in Dromara UJCMS allows manipulation of the username parameter. The CVE description indicates an improper authorization check, meaning an attacker could potentially bypass authentication checks and confirm the existence of user accounts. Based on the nature of this weakness it is inferred that an attacker might be able to access resources that normally require valid authentication, however this capability is not explicitly stated in the CVE data.
Affected Systems
The affected vendor is Dromara, product UJCMS, versions up to and including 12.3.1. Any deployment of these releases that exposes the usernameExist endpoint may be vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk; the endpoint can be accessed remotely, so attackers can launch the exploit over the network. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, so no current public exploitation evidence exists, but the lack of a patch and remote reachability elevate the risk for systems that have not mitigated exposure.
OpenCVE Enrichment