Impact
An insecure permission check in the File API of Uasoft Badaso version 3.0.0‑alpha allows attackers to manipulate the ApiRequest::class function in src/Routes/api.php. The flaw can be triggered remotely via crafted requests, enabling an attacker to bypass the intended authorization controls and gain access to or modify protected files. The impact is a privilege escalation that compromises the confidentiality and integrity of the system’s data.
Affected Systems
The vulnerability affects the Uasoft Badaso product, specifically version 3.0.0‑alpha of the File API component. No other versions or other vendors are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity vulnerability, and the EPSS score is not available, providing no quantitative exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attacker can exploit the flaw remotely by sending crafted API requests to the File API endpoint, exploiting improperly enforced permission checks.
OpenCVE Enrichment