Impact
A flaw in the msgWarning plugin of Kalcaddle Kodbox 1.67 Build 02 allows an attacker to manipulate the /index.php?plugin/msgWarning/action request and bypass normal authorization controls. The vulnerability can be triggered remotely by sending crafted requests, and the published exploit demonstrates its feasibility. As a result, an attacker may gain unauthorized privileges or access to sensitive data exposed by the plugin. The weakness is classified under CWE-266 and CWE-285, indicating inadequate authorisation and privilege management.
Affected Systems
The vulnerable product is Kalcaddle Kodbox version 1.67 Build 02. The flaw exists in the msgWarning Plugin component; no other versions or related products have been identified as affected.
Risk and Exploitability
The CVSS score of 6.9 places this issue in the medium severity range. EPSS data is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but an exploit has already been published. The remote nature of the attack vector means that anyone with network access to the web application may attempt the manipulation without needing authentication. Given the lack of additional mitigations reported by the vendor, the likelihood of exploitation remains significant if the vulnerable plugin is reachable.
OpenCVE Enrichment