Impact
A vulnerability exists in the xianyu-auto-reply server application that allows an attacker to manipulate the /api/v1/payment/withdraw/review endpoint with the action=approve parameter. The flaw causes the server to trust HTTP permission methods supplied by the client, which can bypass intended access controls. This gives an attacker the ability to perform privileged actions, effectively escalating privileges. The weakness corresponds to CWE‑650.
Affected Systems
The affected product is zhinianboke xianyu-auto-reply. No release or version number is specified; the issue seems to affect any instance containing the unpatched /api/v1/payment/withdraw/review endpoint.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. An attacker can remotely exploit the flaw by sending crafted HTTP requests to the endpoint; no additional prerequisites are clearly documented.
OpenCVE Enrichment