Impact
The vulnerability in Zephyr Project Manager is a missing authorization flaw that permits exploitation of incorrectly configured access control security levels. An attacker who can access the plugin’s URLs could elevate privileges or execute actions beyond the permissions granted to their user role, potentially enabling unauthorized project management, data disclosure, or modification. The weakness relies on improper enforcement of role–based restrictions catalogued as CWE‑862.
Affected Systems
The affected product is the Zephyr Project Manager plugin developed by Dylan James, all released versions up to and including 3.3.200. No other vendors or product lines are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not referenced in the CISA KEV catalog. Attackers can potentially target the plugin remotely by sending crafted requests to its endpoints; however, the exploit requires the attacker to discover and exploit the plugin’s insecure security level configuration, which may not be trivially attainable without prior knowledge of the site’s setup.
OpenCVE Enrichment
EUVD