Impact
The vulnerability is a weakness in the authentication logic of Universal Software Inc. E‑Municipality that permits bypassing the normal registration process, enabling an attacker to assume privileged identities without proper credentials. This is a classic authentication bypass flaw, identified as CWE‑305, which undermines the integrity of the authentication system and permits unauthorized access to protected municipal services.
Affected Systems
Universal Software Inc. E‑Municipality build versions from 20251127 up to, but not including, 20260204 are impacted. These releases contain the vulnerable authentication flow that fails to enforce proper identity verification.
Risk and Exploitability
The CVSS score of 5.3 places the flaw in the medium severity range, suggesting a moderate impact if the flaw is successfully exploited. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is currently no evidence of widespread exploitation. The attack vector is not explicitly documented, but the nature of the flaw suggests remote exploitation via the public registration interface, making it potentially reachable over a network. Users should consider the risk of unauthorized privilege escalation when no patch or fix is applied.
OpenCVE Enrichment