Impact
This vulnerability allows unauthorized individuals to read, modify, or abuse stored contact form submissions in the Ishankportfolio website. The issue arises from an improperly secured client‑side database configuration and insufficient access control policies that, when coupled with publicly exposed database credentials or permissive rules, permit attackers to access PII such as names, email addresses, phone numbers, and messages. The impact is a breach of confidentiality and potential misuse of personal information.
Affected Systems
Products impacted are Ishankjha740’s ishankportfolio prior to version 1.0.1. The fix is incorporated in 1.0.1. Any deployment that uses a publicly exposed client‑side database or exposes credentials without restricting access falls into this category.
Risk and Exploitability
The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score of less than 1% indicates a low to very low probability of exploitation, and the solution has not been listed in the CISA KEV catalog. Attackers could exploit the flaw by targeting the public web interface that exposes the database, using exposed credentials or permissive rules to read or alter data. Since the issue is mitigated by upgrading to 1.0.1, organizations should assess whether the database access configuration respects the principle of least privilege.
OpenCVE Enrichment