JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController deleteApply handler that allows any authenticated user to reject tenant administrator applications. Low-privileged attackers can send PUT requests with chosen tenantId, packId and userId values to delete pending applications in any tenant and notify applicants of rejection.
Loading application…