Impact
Vulnerability in the polarlearn API route allows an attacker to send arbitrary vote direction values that bypass normal validation, causing votes to be recorded as downvotes or invalid values. This can alter poll counts and subvert the intended business logic, potentially affecting system integrity and data accuracy.
Affected Systems
PolarLearn, version prior to 0-PRERELEASE-15, is impacted. Any deployment using older versions without the patch is vulnerable.
Risk and Exploitability
With a CVSS score of 7.1, the issue is moderate to high severity. The EPSS score is below 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via the public API endpoint POST /api/v1/forum/vote, where an attacker can supply crafted payloads if no network restrictions are in place.
OpenCVE Enrichment