Impact
This vulnerability arises from an improper authorization check within the RoleInterceptor in OpenBoxes, allowing attackers to manipulate product supplier records. The flaw permits unauthorized modification of supplier data, potentially compromising the integrity of inventory management. The weakness resides in the Product Supplier Edit Controller, which can be exploited remotely with crafted requests.
Affected Systems
Vulnerable OpenBoxes installations running any version up to 0.9.2 are impacted. The issue is confined to the grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy component. Upgrading to version 0.9.3 or a later release that incorporates the commit f767ac1a5987d4865d9f158c6a967680f8e45468 removes the vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability has not been listed in CISA's KEV catalog. The attack vector is remote, and exploitation code is publicly available, making the threat credible under current exposure. Administrators should assess whether their environment exposes the vulnerable endpoint and apply the patch promptly.
OpenCVE Enrichment