Impact
SuiteCRM versions 7.15.2 and 8.10.2 contain a missing authorization flaw in the DetailUserRole entry point that allows any authenticated non‑admin user to query another user’s record identifier in order to read that user’s assigned roles and per‑module access control list matrix. This flaw is a classic CWE‑862 Missing Authorization vulnerability that can leak confidential ACL configuration and potentially support privilege escalation attempts by revealing role assignments and permissions to a non‑privileged user.
Affected Systems
The vulnerability affects all installations of SuiteCRM 7.15.2 and SuiteCRM 8.10.2 only. Any deployment of these specific versions that exposes the DetailUserRole entry point is susceptible; newer releases have addressed the issue and older or other major branches are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, suggesting limited publicly known exploitation. The flaw is exploitable by any authenticated user who has network access to the application, making it a remote authenticated attack vector. Because the impact is limited to disclosure of ACL data and does not directly grant privilege escalation, the overall risk remains moderate, but it is important to remediate to prevent potential future exploitation of exposed role information.
OpenCVE Enrichment