Impact
A flaw in the needManager function of OpenBoxes’ RoleInterceptor.groovy allows an attacker to manipulate privilege checks, granting unauthorized managerial rights. The vulnerability is rooted in improper privilege management (CWE‑266, CWE‑269) and can lead to elevated user privileges, potentially enabling full control over the system. The impact is limited to the attacker's account but can subsequently affect any data or functions accessible with manager rights.
Affected Systems
The bug exists in the OpenBoxes application up to version 0.9.7. It affects the Role Interceptor component of OpenBoxes, a web‑based inventory management system. Upgrading to the 0.9.8‑hotfix1 or 0.9.8 releases applies the fix that corrects the needManager logic.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, but the vulnerability is publicly disclosed and could be used exploit. It is not listed in the CISA KEV catalog. The attack may be launched remotely, exploiting the RoleInterceptor endpoint to alter privilege assignments. Given the public disclosure, the risk of exploitation is non‑negligible for installations that have not applied the hotfix.
OpenCVE Enrichment