Search

Search Results (404217 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108641 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains an insecure direct object reference vulnerability that allows authenticated users to read other users' in-application messages via the getOne handler of SysAnnouncementSendController. Attackers can obtain delivery record ids from the unguarded /sys/sysAnnouncementSend/list endpoint and supply them as the sendId parameter to retrieve message titles, bodies, senders and recipients.
CVE-2026-108640 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartRoleController queryById handler that lacks Shiro permission annotations. Low-privileged authenticated attackers can request GET /sys/sysDepartRole/queryById with any id to read department role names, codes, descriptions and audit fields.
CVE-2026-108639 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows any authenticated user to permanently delete data dictionaries via the deletePhysic handler of SysDictController. Low-privileged attackers can send DELETE requests to /sys/dict/deletePhysic/{id} to irreversibly remove active dictionaries and all their items, bypassing the recycle bin.
CVE-2026-108638 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove group memberships via the deleteGroupUser handler in SysUserController. Attackers can send DELETE requests with arbitrary groupId and userId values to remove any user from any administrator-maintained user group without ownership or tenant checks.
CVE-2026-108637 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to remove user group members by calling DELETE /sys/user/deleteUserGroupBatch. Attackers can supply any groupId and comma-separated userIds to delete sys_ugroup_user rows without permission or tenant checks, tampering with administrator-maintained groups.
CVE-2026-108636 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartController appImportExcel handler that allows any authenticated user to import departments. Low-privileged attackers can upload a crafted Excel workbook to POST /sys/sysDepart/appImportExcel to create arbitrary sys_depart records in the administrator-maintained department tree.
CVE-2026-108635 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the GET /sys/sysDepart/getDepartmentHead endpoint of SysDepartController that allows any authenticated user to list department staff. Low-privileged attackers can enumerate departId values to retrieve staff names, avatars, posts, and mobile and telephone numbers, including contacts marked hidden.
CVE-2026-108634 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to delete department permission bindings via the DELETE /sys/sysDepartPermission/deleteBatch endpoint. Attackers can obtain row ids from the unguarded list endpoint and submit them in the ids parameter to remove menus and buttons departments can grant to their roles.
CVE-2026-108633 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to create department permission bindings via POST /sys/sysDepartPermission/add. Attackers can submit arbitrary departId, permissionId and dataRuleIds fields to attach menu, button and data rule grants to any department for delegation to its roles.
CVE-2026-108632 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController queryById handler that allows any authenticated user to read department permission records. Low-privileged attackers can request GET /sys/sysDepartPermission/queryById with arbitrary ids to retrieve depart_id, permission_id and data_rule_ids for any department.
CVE-2026-108631 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysDepartPermissionController delete handler that allows low-privileged authenticated users to delete department permission bindings. Attackers can obtain row ids from the unguarded list endpoint and send DELETE requests with the id parameter to remove menus or buttons departments can grant their roles.
CVE-2026-108630 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in SysDepartPermissionController that allows any authenticated user to modify department permission records by calling the edit endpoint. Low-privileged attackers can obtain row ids from the unguarded list endpoint and overwrite depart_id, permission_id and data_rule_ids to alter which menus and data rules departments may delegate.
CVE-2026-108629 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDatarule handler of SysDepartPermissionController that allows any authenticated user to modify department data rules. Low-privileged attackers can send departId, permissionId and dataRuleIds to POST /sys/sysDepartPermission/datarule to change, add or clear data rules on any department-menu permission binding.
CVE-2026-108628 1 Jeecg 1 Jeecg Boot 2026-10-10 8.1 High
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any authenticated user to modify department role permissions. Low-privileged attackers can submit roleId and permissionIds values to grant arbitrary menu or button permissions, escalating privileges or revoking other users' permissions.
CVE-2026-108627 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the loadDatarule handler of SysRoleController that lets any authenticated user query role data rules. Low-privileged attackers can request GET /sys/role/datarule/{permissionId}/{roleId} to read rule names, columns, conditions, values and bound rule ids for any role.
CVE-2026-108626 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController queryById handler that allows low-privileged authenticated users to read any message push record. Attackers can supply arbitrary record ids to GET /sys/message/sysMessage/queryById to disclose message content and receiver addresses of other users.
CVE-2026-108625 1 Jeecg 1 Jeecg Boot 2026-10-10 4.3 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability that allows low-privileged authenticated users to modify message push records by calling PUT /sys/message/sysMessage/edit. Attackers can submit a request body naming any sys_sms record id to overwrite its title, content, receiver address and send status without ownership checks.
CVE-2026-108624 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysMessageController deleteBatch handler that allows low-privileged authenticated users to delete message records. Attackers can obtain record ids from the unguarded list endpoint and submit them to deleteBatch to remove any message push records, including pending queued messages.
CVE-2026-108623 1 Jeecg 1 Jeecg Boot 2026-10-10 7.1 High
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to delete system audit log entries. Low-privileged attackers can send a DELETE request with ids set to allclear to wipe the entire sys_log table, erasing all users' audit trails.
CVE-2026-108622 1 Jeecg 1 Jeecg Boot 2026-10-10 5.4 Medium
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController delete handler that allows any authenticated user to delete audit log entries. Low-privileged attackers can obtain log ids from the unguarded /sys/log/list endpoint and delete chosen sys_log records to erase traces of their actions.