Impact
The vulnerability in VINCE’s email notification interface allows a group administrator to modify the email configuration of contacts belonging to other vendors. By accessing a URL that references a raw primary key, the server toggles the email function and name for the targeted contact without verifying that the contact is associated with the requesting administrator’s group. This lack of authorization control enables an attacker to alter notification routing settings or view other vendors’ contact e‑mail addresses, thereby compromising data confidentiality and potentially disrupting communication flow.
Affected Systems
VINCE, the web‑based vendor management platform developed by CERT/CC, is affected. No specific version numbers are provided; any deployment that includes the modified view in vinny/views.py is at risk.
Risk and Exploitability
The issue is an IDOR flaw that can be exercised by an authenticated group administrator. The CVSS v3.1 score for this issue is 5.3, indicating moderate severity. The EPSS score indicates less than 1% likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating that it is not currently known as a widely exploited exploit. Nonetheless, because the attack requires only authenticated access and does not depend on a complex exploit chain, the potential for abuse is high for organizations that rely on VINCE for vendor contact management. Affected administrators could exploit the flaw to change notification routing settings for any vendor contact within the system, potentially exposing sensitive contact information or redirecting notifications.
OpenCVE Enrichment