Impact
Based on the description, the vulnerability permits unauthenticated HTTP access to specific XML files under the web root, which contain plaintext service account and SMTP credentials. Attackers can retrieve these credentials without authentication, compromising confidentiality and enabling further account takeover or malicious mail sending. This weakness is classified as CWE-522.
Affected Systems
The vulnerability affects ICU Scandinavia Boomerang installations. The fix was delivered in version 2.4.18.029 and later releases address the issue.
Risk and Exploitability
Based on the description, it is inferred that attackers can exploit it remotely by issuing simple HTTP requests to the exposed XML files, requiring no authentication. The CVSS score of 7.1 reflects a moderate to high risk. The EPSS score of less than 1% indicates a low but nonzero exploitation probability. The vulnerability is not listed in CISA KEV. Given the sensitive nature of the credentials, the confidentiality impact is considerable.
OpenCVE Enrichment