Impact
A flaw in the AI Provider Configuration Handler of OpenConstructionERP allows an attacker to manipulate session data, causing sensitive information to be exposed to the wrong user session. This weakness is classified as CWE-488, an improper locking issue, where lack of proper session isolation leads to unauthorized data leakage. The vulnerability can potentially grant an adversary access to confidential data that should be restricted to a specific user context.
Affected Systems
OpenConstructionERP from datadrivenconstruction is affected in all releases up to and including version 14.8.1. Users running these versions have been identified as vulnerable; the problem is fixed in version 15.0.0.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, suggesting no data on current exploitation probability, but the flaw is publicly documented and can be triggered remotely. The vulnerability is not listed in the CISA KEV catalog, yet it has been disclosed publicly. The likely attack vector is remote exploitation across the network, potentially by sending crafted inputs to the AI provider endpoint to cause session data leakage.
OpenCVE Enrichment