Impact
The vulnerability is an IDOR flaw (CWE-639) that allows an attacker to supply a user‑controlled key and bypass authorization checks, thereby accessing or executing functionalities that should be restricted. This can lead to unauthorized data retrieval or modification, compromising confidentiality, integrity, and availability of the system’s transaction records.
Affected Systems
Summit Security Systems AdisyonPro before version 5.21.0 is affected. The product is used by organizations that manage point‑of‑sale or transaction processing environments, so the impact could be widespread within deployments that have not applied the hot‑fix.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered medium severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation at the time of analysis. The likely attack vector is via the web interface or API where the user‑controlled key is accepted; an attacker only needs sufficient access to manipulate the request to exploit the flaw.
OpenCVE Enrichment