Impact
Apache Answer lacks an authorization check during the external-login email binding process, allowing attackers to hijack user accounts by delivering a crafted confirmation link that the victim clicks. The flaw is a missing authentication/authorization control (CWE-306) that can result in complete account takeover.
Affected Systems
Apache Answer versions up to and including 2.0.1 are affected. The issue was addressed in version 2.0.2 and later.
Risk and Exploitability
The vulnerability requires an attacker to obtain a victim’s click on a maliciously crafted confirmation link. This social engineering path is relatively low effort, with no additional system access needed to execute the flaw. Exploitation probability is uncertain as the EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw permits unauthorized account takeover, the risk to confidentiality and integrity is substantial.
OpenCVE Enrichment