Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
https://github.com/chillzhuang/SpringBlade/issues/34
https://github.com/chillzhuang/SpringBlade
https://gist.github.com/old6ma/ea60151aa40ddc1cfb51fbaa0c173117