Impact
The vulnerability is a flaw in the Note and Assignment Handlers of Stumasy that allows a remote attacker to supply a crafted assignment_item_id value. Because the system does not check that the caller is authorized to access the specified item, the attacker can bypass authorization controls for note operations. This is an authorization issue (CWE-285) that also involves the misuse of previously granted privileges (CWE-639).
Affected Systems
Stumasy on all builds prior to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be. No specific release numbers are available due model, so any version that predates that commit is at risk until a patch is released.
Risk and Exploitability
The CVSS v3 severity, and the EPSS score of <1% suggests a low likelihood of exploitation. Nevertheless, a public exploit is available and no fix has been released, so the vulnerability can be exploited remotely by manipulating the assignment_item_id parameter in requests processed by the web interface without proper authorization checks. Because it is not listed in the CISA KEV catalog, known exploited vulnerability, but the existence of a public exploit raises concern.
OpenCVE Enrichment