Impact
The vulnerability is a Cross‑Site Request Forgery (CWE‑352) flaw in the Talassoft Industrial Management Software that allows an unauthenticated attacker to submit requests on behalf of a logged‑in user, potentially changing configuration, initiating unauthorized orders, or deleting assets. The flaw can be exploited without knowledge of the victim’s password and may give an attacker the same level of access as the authenticated user, leading to data loss, sabotage, or further compromise.
Affected Systems
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software, versions older than 16 while versions 4 through 15 are specifically vulnerable. Any deployment that has not yet been upgraded to the latest release is exposed.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered medium‑high severity. The attack vector is inferred to be remote via the web interface, relying on a victim’s authenticated session. No published exploit or assault tool is linked, and the vulnerability is not listed in CISA KEV, suggesting a lower immediate exploitation probability. Nonetheless, the potential for unauthorized changes warrants a prompt response.
OpenCVE Enrichment