JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController edit handler that allows any authenticated user to modify AI prompt templates. Low-privileged attackers can send PUT or POST requests to /a...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragPromptsController queryById handler that allows low-privileged authenticated users to read any AI prompt template. Attackers can enumerate ids via the unguar...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController deleteApply handler that allows any authenticated user to reject tenant administrator applications. Low-privileged attackers can send PUT requ...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove users from tenant product packs via PUT /sys/tenant/deleteTenantPackUser. Attackers can supply arbitrary userId ...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to transfer tenant ownership via POST /sys/tenant/changeOwenUserTenant. Low-privileged attackers can supply userId and tenantId parame...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to modify tenant settings by calling PUT /sys/tenant/updateApplyStatus. Low-privileged attackers can supply any tenant id to overwrite...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController listPackByTenantUserId handler that allows any authenticated user to query tenant product packs. Low-privileged attackers can supply arbitrary...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController queryTenantAuthInfo handler that allows any authenticated user to read other tenants' records. Low-privileged attackers can iterate small inte...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to approve tenant administrator applications. Attackers can file a pending application vi...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant administrator applications. Low-privileged ...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the QuartzJobController queryById handler that allows low-privileged authenticated users to read scheduled job records. Attackers can request GET /sys/quartzJob/query...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the OssFileController queryById handler that allows low-privileged authenticated users to read object storage file records. Attackers who know a record id can request...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryPageList handler of OpenApiController that allows any authenticated user to list OpenAPI registry definitions. Low-privileged attackers can query GET /openap...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController updateAvatar handler that allows any authenticated user to change other users' avatars. Low-privileged attackers can send PUT requests with a ...
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getRolesByUserId handler of SystemApiController that allows authenticated users to retrieve any user's role codes. Low-privileged attackers can supply arbitrary u...