Impact
Vimesoft Enterprise Video Platform contains an IDOR flaw that allows anyone with a valid user session to invoke functionality that is not properly restricted by access controls. The flaw is based on a user‑controlled key and can lead to unauthorized access to sensitive video content and administrative actions, thereby compromising confidentiality, integrity, and potentially availability of the platform. The CVSS score of 9.4 reflects the severity of this permission escalation.
Affected Systems
Vimesoft Inc. Enterprise Video Platform versions from 3.11.0.0 up to, but not including, 3.25.0. Users running any of these releases are at risk and should verify their installed version against this range.
Risk and Exploitability
The EPSS indicates that exploitation probability is very low (less than 1%), and the vulnerability is not listed in CISA’s KEV catalog, though it remains a high‑severity flaw. The attack vector is inferred to be through the platform’s web or API interfaces where an attacker can supply the vulnerable user‑controlled key; a valid authenticated session is likely required to reach the affected functionality. Given the lack of formal remediation in the CNA data, the risk is particularly high for organizations that have not upgraded to the patched release.
OpenCVE Enrichment