Impact
ful browsing, allowing an attacker to discover and request URLs that should be protected. The impact is the potential exposure of sensitive information or the ability to perform actions beyond intended permissions. The weakness is classified as CWE‑862.
Affected Systems
Drupal WissKI, versions from 0.0.0 through 4.2.0 are affected.
Risk and Exploitability
With a CVSS score of 6.5, this flaw is assessed as a moderate severity issue. The EPSS score is below 1%, indicating very low exploitation likelihood. It is not listed in the CISA KEV catalog. Based on the description, it can be inferred that the attack vector involves forceful browsing, which can be performed from any network perspective. Because the severity is moderate but the exploitation probability is low, the overall risk is moderate, though it can be higher if sensitive data are exposed or the Drupal site is accessible to untrusted users.
OpenCVE Enrichment