Impact
Wallos is an open‑source subscription tracker. An endpoint responsible for refreshing exchange rates uses a globally stored Fixer/API Layer credential rather than the credential tied to a specific authenticated user. As a result, any authenticated user who does not have a personal provider key can trigger exchange‑rate updates that utilize another user’s stored credential. This gives an attacker the ability to consume another user’s API key and potentially incur unintended costs or affect the other user’s account quota.
Affected Systems
The vulnerability is present in all Wallos releases before v4.9.1. The affected vendor is ellite, and the product is Wallos, a self‑hosted personal subscription tracker used by individuals and organizations.
Risk and Exploitability
The CVSS v3.1 base score of 4.3 indicates a medium severity. An attacker must be an authenticated user of the application to exploit the flaw; there is no remote code execution or system compromise, nor is it currently listed in CISA’s KEV catalog. Because no EPSS score is available, the current exploitation probability is unknown, but the impact is limited to misuse of another user’s API key for exchange‑rate retrievals. The vulnerability would not directly expose sensitive user data, but it could lead to unnecessary API calls, quota exhaustion, or hidden charges.
OpenCVE Enrichment