Impact
The vulnerability arises from improper handling of the isAdmin/jobId arguments in OrgStaffServiceImpl.add within the api‑admin backend. This results in an authorization bypass that allows attackers to execute privileged functions without proper authentication, granting unauthorized access or privilege escalation. The weakness corresponds to CWE‑266 (Special‑Cased Authorization) and CWE‑285 (Improper Authorization) and could lead to unauthorized modification or disclosure of sensitive data.
Affected Systems
The affected product is realjerrytang tacomall, version 1.0.0. No additional versions are listed in the CVE data, so only this release is confirmed to have the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. No EPSS score is available, but the advisory notes that a public exploit is available and remote exploitation is possible. The flaw has not been listed in the CISA KEV catalog. Attackers could remotely exploit the vulnerability by manipulating the isAdmin and jobId parameters in HTTP requests, bypassing authorization checks.
OpenCVE Enrichment