Impact
R‑SOFT DMS exposes a classic insecure direct object reference flaw where any authenticated user can supply a file identifier and download files without ownership validation. The weakness, classified as CWE‑639, allows a user to obtain confidential documents stored on the server, leading to loss of confidentiality and potential regulatory penalties if sensitive data is compromised.
Affected Systems
The vulnerability affects R‑SOFT SERWIS DMS versions prior to v3.19‑2862 and v3.17‑2580. Any installation of these releases is susceptible to IDOR exploitation.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. The EPSS score of less than 1% suggests that mass exploitation is currently unlikely, and the issue is not listed in CISA’s KEV catalog. An attacker must possess a valid user session; with that access, they can modify request parameters to retrieve files belonging to other users. The description does not mention any public exploits, but the flaw enables data disclosure to any authenticated user.
OpenCVE Enrichment