Impact
Kiteworks Core contains a business logic flaw in a file-request feature that allows an authenticated user to send a request that appears to originate from another user because the server does not verify that the requester is authorized to act as the specified account. This flaw can be exploited to solicit files or information from a recipient under a trusted identity. The weakness is a classic example of authorization bypass (CWE-639).
Affected Systems
The affected system is Kiteworks Core. No specific product versions are listed, but the flaw exists wherever the file-request feature is enabled for a user profile.
Risk and Exploitability
The CVSS score of 4.6 indicates a moderate impact. An attacker must first have an authenticated user account with the file-request feature enabled, and the targeted recipient must act on the impersonated request. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, which suggests that widespread exploitation may not yet be observed. The likely attack vector involves legitimate, authenticated users abusing the feature to impersonate other users within the internal environment.
OpenCVE Enrichment