Impact
A vulnerability was identified in the WonderTrader application, specifically within the file WTSTradeDef.hpp of the TraderATP Cash Trade Conversion component. The bug allows manipulation of the m_offsetType argument to cause the program to use an uninitialized variable, which can lead to unpredictable behavior or accidental data exposure. The CVSS score of 5.3 indicates a medium severity risk, and the exploit was publicly disclosed and is known to be exploitable from a remote location.
Affected Systems
The flaw affects all installations of WonderTrader up to version 0.9.9. No patch or update has been publicly released by the vendor, and the vendor has not provided a response to the disclosure. Consequently, any systems running a vulnerable version are exposed.
Risk and Exploitability
Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the exact likelihood of exploitation in the wild is uncertain. However, the remote attack vector coupled with the medium CVSS score suggests that attackers could feasibly trigger the defect to corrupt internal state or leak data. As the vulnerability can be reproduced by supplying crafted input, it should be treated with caution until a patch or mitigation is applied.
OpenCVE Enrichment