Impact
lamp-cloud through 5.10.0 contains an authorization bypass flaw in the getUserInfoById endpoint that permits any authenticated user to read the full profile of any other user. The data exposed includes phone numbers, email addresses, national identity card numbers, and social media identifiers such as WeChat or DingTalk OpenIDs, making the vulnerability a serious privacy violation.
Affected Systems
The affected product is dromara lamp-cloud, versions up to and including 5.10.0. Any deployment of these versions that exposes the getUserInfoById endpoint without proper access controls is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of this vulnerability, and the EPSS score is not available, meaning there is no publicly known exploitation rate yet. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the flaw by sending a correctly authenticated HTTP request to the getUserInfoById endpoint with a userId parameter that cycles through known user identifiers; the likely attack vector is via normal web traffic from any user possessing valid credentials.
OpenCVE Enrichment