Impact
The identified issue resides in the /system/downloadById endpoint of MineAdmin 1.x and 2.x. By manipulating the ID argument, a caller can trigger the download of files that were not intended for public disclosure, leading to the leaking of potentially sensitive data. This flaw falls under the Information Exposure and Improper Access Control weaknesses.
Affected Systems
MineAdmin versions 1.0 and 2.0, along with any 1.x and 2.x releases, are impacted by this vulnerability.
Risk and Exploitability
The vulnerability has a low CVSS score of 2.3 and an EPSS score below 1 %, indicating a low overall severity and a very small probability of exploitation in the wild. Nonetheless, the attack can be initiated remotely, requires high complexity and is considered difficult to exploit, yet the public exploit may be leveraged by an attacker with network access to the MineAdmin instance. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment