Impact
A low‑privileged attacker who has a valid session can send a request to the /api/user/add.php endpoint and create new accounts with arbitrary role values, including the highest privilege level used by the application. This incorrect authorization flaw, classified as CWE‑863, allows attackers to elevate privileges, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
Frauscher Sensortechnik’s FDS 102 platform is affected. No specific versions were identified in the available data, so all releases of this product should be considered vulnerable unless a patch has been applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. The EPSS score of less than 1% suggests a low probability of exploitation in the short term, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, the attack can be carried out remotely over the network by any user with a low‑privileged account that can access the exposed endpoint, allowing the attacker to generate accounts with the highest level of access.
OpenCVE Enrichment