Impact
A weakness in the TicketDetailView function of Ehco1996’s django‑sspanel allows an attacker to bypass authorization checks. By manipulating the request, a user with no legitimate access can view or interact with support tickets, potentially exposing sensitive customer data or altering ticket information. This constitutes a classic authorization bypass flaw, as indicated by CWE‑285 (Improper Authorization) and CWE‑639 (Authorization Bypass Through User‑Controlled Key).
Affected Systems
The vulnerability is present in all releases of Ehco1996’s django‑sspanel up through version 2023.12.26, a product that is no longer maintained or supported by the original maintainer.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is considered moderate in severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The description notes that the attack can be performed remotely, suggesting that remote users can exploit the flaw if they have network access to the application. No exploit has been publicly disclosed, but the lack of a patch and ongoing support increases the risk of undetected exploitation.
OpenCVE Enrichment