CVE-2023-38990

MEDIUM

Jeesite <1.2.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus created by the Administrator.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (1)
jeesite/jeesite 1.2.6
Published Aug 02, 2023
Tracked Since Feb 18, 2026