Impact
The vulnerability is an IDOR flaw that permits an attacker to bypass authorization by providing a user‑controlled key. This flaw allows a legitimate user to access or modify resources that should be restricted, potentially exposing confidential data or enabling unauthorized manipulation of workflow information. The weakness corresponds to CWE‑639, indicating an authorization bypass through a user‑controlled key.
Affected Systems
The affected product is Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System, with all releases up to version 12022026. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the moderate-to-high severity range, while an EPSS of less than 1% indicates a low current likelihood of exploitation but does not preclude the possibility. The flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. The likely attack vector involves client‑side manipulation of a key that governs access to protected resources, allowing an attacker with knowledge of the key structure to retrieve or modify data they should not normally access.
OpenCVE Enrichment