Impact
The vulnerability resides in the password reset functionality of MobiAPParc, where an attacker can modify the numeric user_id parameter that identifies the account. By changing this predictable identifier, an attacker can reset the password of any user without evidence of ownership, leading to unauthorized account access and potential data compromise.
Affected Systems
Affected systems are installations of the MobiAPParc application. The CNA lists only MobiAPParc itself; specific version information is not provided, but the issue exists until the latest release that incorporates the fix. All users of older releases could be impacted.
Risk and Exploitability
The CVSS base score of 8.8 signals high severity, and although EPSS data is not available, the lack of a KEV listing does not diminish the risk. Attackers can exploit the flaw remotely via the web interface, submitting forged requests with altered user_id values. Once a password is reset, the attacker gains full control of the victim's account, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment