Executive brief
lamp-cloud is a microservices rapid development platform for enterprise backend systems. An authorization bypass vulnerability in the getUserInfoById endpoint allows authenticated employees to read other employees' sensitive personal information by iterating user IDs, exposing mobile numbers, email addresses, national ID numbers, and linked social media accounts without proper access controls.
Technical details
The getUserInfoById endpoint in UserInfoController accepts a userId parameter with no ownership verification; if userId is null, it defaults to the current user, but when a specific userId is provided, the OauthUserBiz.getUserById() method returns the entire user record including PII fields without checking authorization. The endpoint lives under /anyone/**, which requires only authentication (not specific permissions), allowing any logged-in user to enumerate and harvest full profiles of other users. No user interaction or elevated privileges are required beyond valid credentials.
Affected products
- dromara lamp-cloud through 5.10.0
Timeline
- 2026-09-21: disclosed