Impact
The vulnerability affects MineAdmin versions 1.x and 2.x and is located in a function of the /system/cache/view file within the View Interface component. By manipulating this endpoint, an adversary can bypass the intended authorization checks and gain access to views or operations that should be restricted. This flaw is remotely exploitable, and an exploit has been made publicly available, allowing a malicious actor to carry out the attack from any network where the target is reachable.
Affected Systems
MineAdmin versions 1.x and 2.x are affected. The Common Platform Enumeration entries list the 1.0 and 2.0 releases. Any installation using these versions is exposed, regardless of deployment size or hosting environment.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates a moderate impact, focusing primarily on confidentiality and integrity through improper authorization. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at the present moment, and the vulnerability is not catalogued in the CISA KEV list. Nevertheless, because the flaw can be triggered remotely without special credentials and the exploit is publicly available, administrators should consider remediation early to prevent unauthorized data exposure.
OpenCVE Enrichment
Github GHSA