Impact
A remote attacker can manipulate the ID argument in the /api/undo/ Delete Category Handler, causing the system to allow deletion of categories without proper authentication. This flaw falls under CWE-266 (Retained Secret) and CWE-285 (Improper Authorization), leading to unauthorized changes that compromise the integrity and availability of annotation data.
Affected Systems
The vulnerability affects jsbroks COCO Annotator versions up to and including 0.11.1.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score is below 1 %, reflecting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, but a public exploit is available. Exploitation requires remote API access to the undo endpoint and manipulation of the ID parameter. While the chances of exploitation are currently low, the potential impact warrants timely remediation.
OpenCVE Enrichment