Impact
lamp‑cloud versions up to 5.10.0 lack identity validation on the PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, enabling an authenticated user to specify another user’s ID in the request body. This allows the attacker to rewrite profile fields such as nickname, ID card, sex, nation, education, work description and the avatar attachment, effectively compromising the integrity and privacy of other user accounts.
Affected Systems
The affected product is lamp‑cloud from dromara, specifically all releases through 5.10.0.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1 indicating a medium‑high severity. No EPSS data is available and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is network‑based; an authenticated user merely needs to send a crafted HTTP PUT request to the vulnerable endpoints. The exploitation requires only valid authentication and no additional privileged access, making it relatively easy to exploit in an environment where the attacker has legitimate login credentials or can obtain them.
OpenCVE Enrichment