Impact
Netiket Information Technologies EdoWEB suffers from an IDOR flaw in which a user‑controlled key bypasses ACL checks, allowing an attacker to invoke protected functionality that should be restricted. The vulnerability, classified as CWE‑639, can lead to unauthorized actions or exposure of sensitive data within the application.
Affected Systems
The affected product is Netiket Information Technologies EdoWEB. Versions prior to 780‑g7 contain the flaw; the patch is included in release 780‑g7 and later.
Risk and Exploitability
The CVSS base score of 5.3 denotes a moderate severity, but the EPSS score is unavailable and the issue is not listed in the CISA KEV catalog, indicating no known active exploits. It is inferred that the attack vector is a web request where an attacker manipulates the key parameter to gain unauthorized access. Given its moderate severity and potential for privilege escalation, monitoring and timely remediation are advised.
OpenCVE Enrichment