Impact
The Vitepos plugin contains a missing authorization vulnerability that allows an attacker to perform actions that should be restricted to authenticated or privileged users. The flaw arises from improperly configured access control security levels, making functions intended for authorized users reachable by anonymous or unauthenticated users. This can result in unauthorized read or write of data and potentially compromise user content.
Affected Systems
The vulnerability affects the Vitepos lite plugin from appsbd. Any installation with a version equal to or older than 3.1.3, or any version released before the first version of the plugin, is impacted. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw permits unauthenticated or unauthorized access through the plugin’s web interface, a remote attacker could potentially exploit it by crafting HTTP requests to the affected endpoints. No known mitigations have been documented by the vendor; therefore, the attack vector is inferred to be through the web interface.
OpenCVE Enrichment
EUVD