Impact
DrEryk Gabinet versions prior to 11.5.0 embed hard‑coded API credentials within the ticket reporting component. These credentials allow an attacker to authenticate directly to the ticket system API, bypassing normal user authentication controls. Once authenticated, the attacker can execute any privileged operation that the API supports, such as viewing, editing, or deleting tickets. This grants the attacker significant control over ticket data and workflow, potentially enabling fraud or data leakage.
Affected Systems
The affected product is drEryk Gabinet from the vendor drEryk, specifically all releases prior to version 11.5.0. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 classifies the vulnerability as medium severity. The EPSS score is not available, so the current exploitation probability is unknown, and the issue has not been recorded in the CISA KEV catalog. The exploit requires that the application’s ticket reporting endpoint is reachable; the hard‑coded credentials are embedded in the code, so an attacker can use them immediately after discovering the endpoint. The attack is likely remote but does not require privileged access to the host itself, relying only on the exposed API.
OpenCVE Enrichment