Impact
A GET endpoint at /invitations/{uuid} was able to perform a state‑changing password reset when supplied The attacker can set the victim, giving the attacker full control of the victim’s account. This request forgery (CWE‑352) that compromises account confidentiality and integrity.
Affected Systems
The vulnerability affects installations of Coolify produced by coollabsio that run any prior to version 4.0.0‑beta.471.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability, while the EPSS score of < 1% shows a very low likelihood of exploitation in the wild. The issue is not listed in CISA’s KEV catalog. The likely attack vector is a crafted link that, when visited by the victim, triggers the GET request. The attacker needs only to persuade the target user to click the URL; no special privileges or additional exploits are required. Successful exploitation gives the attacker full control of the account.
OpenCVE Enrichment