Impact
lamp‑cloud versions up to 5.10.0 contain a flaw in the FileAnyoneController that bypasses file‑ownership checks. An authenticated user can request any file by supplying its attachment identifier to the /anyone/file/down or /anyone/file/download endpoints, and the application does not compare that identifier against the creator or owner of the file. This allows a user to read other users’ private uploads, leaking confidential data without needing any additional privileges.
Affected Systems
The vulnerability affects the dromara lamp‑cloud product, specifically all releases through version 5.10.0. No sub‑versions or service packs are listed as unaffected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability that can be abused by any authenticated user within the system. Because the exploit simply requires a valid attachment ID and no elevation of privileges, the attack is easy to perform once the attacker has legitimate login credentials. EPSS data is unavailable, and the flaw is not listed in CISA KEV, but the impact of leaking sensitive files warrants careful attention.
OpenCVE Enrichment