Impact
The flaw resides in the GetOrderAsync function of the Ordering API within the dotnet eShop project. By manipulating the OrderNumber argument, a requester can control resource identifiers in an improper manner, enabling a form of resource injection that falls under CWE-99. This allows an attacker to request data for arbitrary orders or resources that should be otherwise inaccessible, potentially exposing sensitive information or disrupting normal service.
Affected Systems
dotnet eShop (Ordering API) built on .NET 8. The vulnerable code is located in src/Ordering.API/Apis/OrdersApi.cs and is part of the dotnet eShop repository. Affected version information is not available.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack can be carried out remotely by providing a crafted OrderNumber value to the Orders API endpoint. Because the impact involves unauthorized access to order resources, the potential for data leakage or service disruption exists, especially if it is inferred that authentication or input validation controls are weak or absent.
OpenCVE Enrichment