Impact
The vulnerability is an information disclosure and control flaw that allows an authenticated user to supply a user‑controlled key and bypass PAVO Pay’s authorization checks. By presenting a trusted identifier that does not belong to them, an attacker can access data or perform actions reserved for the legitimate owner, leading to unauthorized information disclosure or transaction manipulation. The flaw is classified as CWE‑639, an authorization bypass through a user‑controlled key.
Affected Systems
The vulnerability affects PAVO Financial Technology Solutions Inc.’s PAVO Pay product. Versions up to and including 09072026 are vulnerable; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is low at present. The vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely exploited. The likely attack vector is inferred to be via manipulated HTTP requests where the user supplies a user‑controlled key; the lack of an explicit description leaves the exact exploitation pathway unspecified, but typical IDOR behavior would apply.
OpenCVE Enrichment