Impact
A flaw in the TraderDD::queryTrades function located in src/TraderDD/TraderDD.cpp allows manipulation of the FID_JYLB argument to enforce unintended business logic, effectively permitting unauthorized actions or bypassing controls. The vulnerability is linked to CWE-840 and CWE-841. Attack can be launched remotely, requires high complexity, and is considered difficult to exploit, yet a public exploit is now available. With a CVSS score of 6.3, the issue is classified as moderate severity and could have significant impact on system integrity and business processes.
Affected Systems
WonderTrader WonderTrader versions up to and including 0.9.9 are susceptible to this issue. No other release versions are known to be affected.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate risk to environments hosting the vulnerable product. The EPSS score is not available; the description notes that exploitability is considered difficult, suggesting that widespread attacks are unlikely. The vulnerability is not listed in CISA KEV, yet an active public exploit exists, meaning attackers could potentially leverage it against exposed systems. Remote exploitation would entail invoking the queryTrades API with a crafted FID_JYLB value, so protection can be achieved by restricting network access or monitoring anomalous calls.
OpenCVE Enrichment