See how jeecgboot compares to other vendors in security performance
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController getUserDetailByUserId handler that allows any authenticated user to read other users' details. Low-privileged attackers can supply arbitrary userId values to retrieve real names, usernames, emails, phone numbers, birthdays, employee numbers, department paths and posts.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController exportXls handler that allows any authenticated user to export department roles. Low-privileged attackers holding only the default minimal role can call /sys/sysDepartRole/exportXls to download all sysdepartrole records, including role names, codes, descriptions and creating users.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController delete handler that allows low-privileged authenticated users to delete message records. Attackers can send DELETE requests with arbitrary id values to remove any syssms row, erasing records of sent notifications without ownership checks.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the PUT /sys/dict/editDictByLowAppId endpoint that allows any authenticated user to modify low-code application dictionaries. Attackers can supply a dictionary's lowappid, obtained from GET /sys/dict/list, via the lowAppId parameter or X-Low-App-ID header to rename dictionaries and replace their items.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the editThirdAppConfig handler that allows any authenticated user to modify third-party application configurations. Low-privileged attackers can replace client id, client secret, agent id and corp id of DingTalk, WeCom or Feishu integrations to redirect directory synchronisation and messaging to attacker-controlled applications or break them.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysPositionController removeUserPosition handler that allows any authenticated user to remove position members. Low-privileged attackers can send DELETE requests with arbitrary userIds and positionId values to delete sysuserposition rows, detaching users from positions without logging.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController queryChildrenByUsername handler that allows any authenticated user to retrieve other users' account records. Low-privileged attackers can supply arbitrary userId values to obtain names, emails, phone numbers, employee numbers, department assignments, and staff lists of departments those users head.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the getTenantPackInfo handler that allows any authenticated user to read other tenants' product pack membership. Low-privileged attackers can supply a tenantId and fixed packCode values such as superAdmin, accountAdmin or appAdmin to disclose administrator usernames, real names, phones and departments.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageTemplateController delete handler that allows any authenticated user to delete message templates. Low-privileged attackers can obtain template ids from the unguarded list endpoint and delete shipped notification templates, causing system notices and workflow reminders to fail.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysCommentController exportXls handler that allows any authenticated user to export all comments. Low-privileged attackers can request /sys/comment/exportXls to download every syscomment row, including comment text and user ids on records they cannot access.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the putCancelQuit handler of SysUserController, allowing any authenticated user to cancel user resignations. Low-privileged attackers can supply user ids and a tenantId parameter or X-Tenant-Id header to restore ended, pending, or refused tenant memberships to normal.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify any department by calling PUT /sys/user/doUpdateDepartInfo. Attackers can supply a department id to rename or re-parent it and replace or remove its department heads without ownership or tenant checks.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragAppController queryById handler that allows low-privileged authenticated users to read any AI application configuration. Attackers can enumerate application ids via the unguarded /airag/app/listDict endpoint and query each id to obtain system prompts, memory prompts, model ids, knowledge base ids, and plugin bindings of other users' applications.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in AiragPromptsController that allows any authenticated user to delete AI prompt templates by calling DELETE /airag/prompts/delete. Low-privileged attackers can obtain template ids from the unguarded GET /airag/prompts/list endpoint and logically delete any user's prompt template, making it unavailable to all users.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysUserController addSysUserGroup handler that allows any authenticated user to modify user group membership. Low-privileged attackers can send POST requests with arbitrary user ids and a groupId to add any users to administrator-maintained groups without permission checks.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to assign or remove department heads by calling PUT /sys/user/changeDepartChargePerson. Low-privileged attackers can supply arbitrary userId, department id, and status values to make any user a department head, widening department-scoped views, or demote existing heads.
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability in AiragBaseApiController that allows authenticated users to read other users' AI chat variables via the username parameter. Attackers can send POST requests to /airag/api/getChatVariable with a target appId, username, and variable name to retrieve stored chat memory values from Redis.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the batchEditUsers handler of SysUserController that allows any authenticated user to edit user department assignments. Low-privileged attackers can send PUT requests to /sys/user/batchEditUsers with arbitrary user and department ids to move users, including administrators, between departments and overwrite positions.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SystemApiController getUserRoleSetById handler that allows any authenticated user to read other users' role assignments. Low-privileged attackers can supply an arbitrary userId parameter to retrieve assigned role codes and identify administrator accounts without the system:user:queryUserRole permission.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows authenticated users to read any account's permissions via the queryUserAuths handler. Low-privileged attackers can supply an arbitrary userId parameter to retrieve another user's complete permission set and identify administrator accounts.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysRoleController saveDatarule handler that allows low-privileged authenticated users to modify role data rules. Attackers can send permissionId, roleId and dataRuleIds to overwrite dataruleids, clearing row-level filters to widen readable records or altering filtering for other roles.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to send system announcements by calling POST /sys/api/sendSysAnnouncement. Attackers can supply arbitrary title, content, fromUser and toUser values to deliver forged announcements to any users via WebSocket, WeCom, DingTalk and Feishu.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to publish templated system announcements via POST /sys/api/sendBusTemplateAnnouncement. Low-privileged attackers can supply templateCode, toUser, and a forged fromUser to send notifications to arbitrary users through WebSocket, DingTalk, WeCom, Feishu and UniPush channels.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartRoleController that lets low-privileged authenticated users modify department role data rules. Attackers can send crafted permissionId, roleId and dataRuleIds values to overwrite dataruleids, widening row-level data access or altering filtering for other department roles.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to send template notifications by calling POST /sys/api/sendTemplateAnnouncement. Low-privileged attackers can supply forged sender, recipients, title, and template parameters to deliver messages appearing to come from admin or system accounts.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the sendBusAnnouncement handler of SystemApiController that allows any authenticated user to send announcements without the required permissions. Low-privileged attackers can POST crafted bodies to /sys/api/sendBusAnnouncement with forged sender, recipients, title and content to deliver spoofed admin or system messages for phishing.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysAnnouncementController editIzTop handler that allows low-privileged authenticated users to change announcement pin status. Attackers can send POST or PUT requests with any announcement id to pin or unpin system notices shown at the top for all users.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in GET /sys/api/getUserByName that allows low-privileged authenticated users to retrieve any user's stored password value. Attackers can decrypt the AES-CBC protected response using the hard-coded key exposed by /sys/getEncryptedString to obtain administrators' password ciphertexts for offline guessing.
JeecgBoot through 3.9.5 contains an authorization bypass vulnerability in the getVideoRecords handler of VideoGenerationController that allows authenticated users to read other users' records via the userId parameter. Low-privileged attackers can supply another user id to retrieve their AI video generation history, including prompts, task ids, video URLs and cover URLs.
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the queryUserRoles handler of SystemApiController that lets authenticated users read any user's role codes. Low-privileged attackers can send GET requests to /sys/api/queryUserRoles with an arbitrary username to enumerate role assignments and identify administrator accounts.