Impact
Chiline Cloud, developed by Inventec Appliances, has an insecure direct object reference vulnerability that allows unauthenticated remote attackers to alter a specific parameter and read other users' sensitive data. The flaw, identified as CWE‑639, can lead to unauthorized disclosure of confidential information. This attack does not modify data or grant code execution, but it exposes sensitive data that could be used for further exploitation.
Affected Systems
The vulnerability affects the Inventec Appliances Chiline Cloud platform. No specific affected product versions are listed in the advisory, and version details are not available in the supplied data.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating a high severity impact. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog. Attackers can exploit the flaw remotely and unauthenticated by manipulating a URL or API parameter that accesses user data. The service provider has resolved the issue at the cloud level, so customers are not required to take action.
OpenCVE Enrichment