Impact
In BookCars version 8.3, authentication controls on the type field of user accounts are improperly enforced. Based on the description, it is inferred that an authenticated user can modify the "user type" field in their own profile to elevate themselves from a normal user to an administrator. This flaw represents a classic missing authorization weakness, allowing a user to acquire rights that should be restricted to higher‑privileged accounts.
Affected Systems
The vulnerability affects the BookCars application, specifically release 8.3. No other versions are listed as affected, and the vendor is not identified by the CNAs.
Risk and Exploitability
Based on the description, it is inferred that the flaw is exploitable by anyone who can log into the application, making the attack vector internal or local. The CVSS score is 8.1, indicating a high severity vulnerability. The ability to switch to admin grants unrestricted access to all application functions, database tables, and possibly underlying host data. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The low barrier to exploitation indicates a significant risk for any system running BookCars 8.3.
OpenCVE Enrichment