Impact
An insecure direct object reference exists in MK-Auth 23.01K4.9 that permits an attacker to manipulate the chamado parameter in a crafted GET request. This flaw allows the attacker to view and send support calls on behalf of other users, violating confidentiality and integrity of user support data. The vulnerability is an example of an IDOR weakness, where insufficient checks enable manipulation of object identifiers.
Affected Systems
The vulnerability affects the MK-Auth application version 23.01K4.9. No additional vendor or product names are listed, so all installations of this version are potentially impacted.
Risk and Exploitability
The CVSS score is 5.4, and the EPSS score is < 1%. The flaw is a direct object reference that can be triggered via a simple GET request, indicating a low barrier to exploitation. The CISA KEV status is not listed, so no known exploitation activity is catalogued. The likely attack vector is remote web request, and the impact is limited to unauthorized access to support calls, not full system compromise.
OpenCVE Enrichment