Impact
The vulnerability arises from client-side enforcement of server-side security rules in Gobito's Corporate Training Management System. Because access controls and state transitions are validated only in the browser, an attacker can craft input that bypasses legitimate business logic, potentially granting unauthorized access to training records or manipulating progress metrics. This results in a confidentiality or integrity breach of training data and could compromise audit trails. The flaw is classified as CWE‑602, Business Logic Errors.
Affected Systems
Vulnerable versions are those before the commit dd1a9df64 of the Corporate Training Management System produced by Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. No specific product sub‑versions are listed, so any release containing the identified client‑side enforcement mechanism is affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Because the EPSS score is not available, the current probability of exploit remains unknown, and the vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires an attacker with the ability to inject or alter client‑side data, such as a compromised user account or access to the application’s web interface. Without server‑side validation, the business logic bypass can be triggered manually or through crafted requests, making the attack relatively straightforward for a motivated adversary.
OpenCVE Enrichment