Impact
Prior to version 4.9.1, a logged‑in user can edit their own inactive subscription and assign a replacement_subscription_id that points to another user’s subscription. The update succeeds and later the statistics logic dereferences that foreign subscription ID without scoping to the user, allowing the attacker to infer the victim’s monthly‐normalized cost by simply observing changes to their own statistics. The flaw does not expose the full subscription object, but it does reveal derived financial metadata.
Affected Systems
Wallos, a self‑hosted personal subscription tracker from ellite, is impacted by any installation running a version older than 4.9.1. All releases prior to 4.9.1 carry this vulnerability.
Risk and Exploitability
The CVSS score of 4.3 places this weakness in the moderate threat class; EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authentication and the ability to edit a subscription, so the exploitation vector is limited to legitimate credentials. Once executed, the attacker learns the target’s subscription cost but cannot retrieve full subscription details or modify them.
OpenCVE Enrichment