CyberRota Analysis
AI-GeneratedX-SpringBoot versions up to 6.0 are vulnerable due to insufficient object-level authorization in user management endpoints, enabling sub-administrators to modify or delete user accounts without proper ownership verification. This flaw allows attackers with user-management permissions to reset passwords for any account, including super administrators, and to alter or delete user roles. Organizations utilizing X-SpringBoot should prioritize patching this vulnerability to prevent unauthorized access and potential account takeovers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users via POST /sys/user/update and POST /sys/user/delete endpoints.