Impact
lamp-cloud versions through 5.10.0 contain an authorization bypass that lets any authenticated user delete notifications of other users. The vulnerability is exposed via the DELETE /anyone/extendNotice/deleteMyNotice endpoint, which accepts arbitrary notice identifiers without validating that the requester is the intended recipient. This flaw results in unintended data loss and can reveal or erase user‑specific information, constituting a privacy violation and potential denial of service for affected users. The weakness is classified as CWE-639.
Affected Systems
The affected product is lamp‑cloud from dromara, with all releases up to and including version 5.10.0 vulnerable. No other vendor or product versions are listed as affected.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is no current evidence of widespread exploitation, but the active nature of the endpoint and the lack of recipient validation make this flaw readily exploitable by any user with legitimate credentials. Attackers could programmatically send deletion requests for arbitrary notice IDs, permanently removing data from other accounts without further checks.
OpenCVE Enrichment