Impact
The nl.nl-portal:taak component within NL Portal Backend Libraries implements a GraphQL mutation called submitTaakV2 that records user tasks. The implementation does not verify task ownership, allowing any authenticated user who knows or can guess another user’s task identifier to read the form data, overwrite the submitted data and mark the task as completed. This flaw corresponds to CWE‑639 and permits unauthorized read, modification, and completion of another user’s task data, potentially exposing sensitive information or altering business logic.
Affected Systems
Affected components are part of the nl-portal backend libraries, specifically the nl.nl-portal:taak package. Versions from 1.5.0 through 3.0.0 lack proper ownership checks; the issue was addressed in 3.0.1. No other product versions are listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, categorising it as high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation in the short term, and the weaknesses is not listed in the CISA KEV catalog. Exploitation requires only an authenticated session and knowledge of a valid task ID, which can often be discovered through enumeration or guesswork. The lack of access control permits attackers to tamper with or complete tasks that belong to other users, potentially impacting confidentiality, integrity and availability of user data.
OpenCVE Enrichment
Github GHSA