Impact
Rhym31 is vulnerable to an insecure direct object reference (IDOR) that allows an attacker to read arbitrary files by supplying additional variables in a request. This flaw can expose sensitive configuration files, user data, or other files stored on the server, leading to a confidentiality breach. The weakness is classified as CWE-425.
Affected Systems
The affected product is Rhymix from the Rhymix organization. Any deployment running Rhymix before version 2.1.31 is vulnerable. The vulnerability is present in all versions older than 2.1.31.
Risk and Exploitability
The CVSS score of 7.4 rates this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires sending a crafted web request containing extra variables to trigger the IDOR. No authentication or privileged access is mentioned, so the attack may be possible from any external user, implying a wide attack surface.
OpenCVE Enrichment