Impact
The vulnerability lies in the Session Attribute Handler component of PSI Probe, specifically within the RemoveSessAttributeController. An attacker can manipulate the removal of session attributes, leading to unauthorized access or privilege escalation. This flaw is caused by improper access controls and is identified as CWE-266 and CWE-284.
Affected Systems
Psi‑Probe PSI Probe versions up to 5.3.0 are affected. The flaw is located in psi-probe-core/src/main/java/psiprobe/controllers/sessions/RemoveSessAttributeController.java and applies to any deployment using the Session Attribute Handler in those releases.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity, while the EPSS score of less than 1 percent reflects a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely with publicly available code, but no further exploitation prerequisites are documented beyond the manipulation of the controller’s access controls.
OpenCVE Enrichment