Impact
The vulnerability is an Insecure Direct Object Reference that allows an unauthenticated attacker to download an Excel file containing usernames, full names, email addresses and phone numbers of all users enrolled in a course. This data exposure constitutes a breach of confidentiality and is mapped to CWE‑284, missing access control.
Affected Systems
Affected is the Educativa Campus application. The vulnerable version reported is 14.05.00-35; the fix is available in 14.05.00-159 and later. Versions older than the fix are likely impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower immediate risk of widespread exploitation. However, because the vulnerable endpoint is accessible without authentication and accepts a course identifier as a query parameter, an attacker can brute‑force course IDs to enumerate and retrieve user data. The exploit is straightforward once the target URL is known, making it potentially attractive to attackers who wish to harvest personal information.
OpenCVE Enrichment