Impact
Ahsay AhsayCBS contains a flaw in the checkSysPwd function of the ApiStructsAction component that permits attackers to bypass authentication by manipulating the random argument. This vulnerability is a classic example of improper authentication (CWE-287) and could allow an attacker to gain unauthorized access to the system’s API endpoints, potentially exposing sensitive data or enabling further exploitation.
Affected Systems
The vulnerability affects Ahsay AhsayCBS versions up to 10.3.2. Ahsay released mitigation in version 10.3.4, which should be applied to eliminate the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the vulnerability is exploitable remotely. Although EPSS data is not available and the issue is not listed in CISA KEV, the public nature of the exploit and the ability to trigger it by manipulating an input argument make it a realistic threat. Proper authentication checks are not enforced when the random parameter is altered, allowing attackers to impersonate legitimate users without needing valid credentials.
OpenCVE Enrichment