Impact
An issue in Invixium IXM WEB version 2.3.85.25 allows attackers to gain higher privileges by abusing the /SystemUsers/CreateAppUser component. This weakness, identified as a lack of proper authorization checks (CWE-269), permits privileged operations that should be restricted to authorized administrators.
Affected Systems
Invixium IXM WEB version 2.3.85.25 is affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity risk. The EPSS score is less than 1%, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector involves accessing the web interface and sending requests to the /SystemUsers/CreateAppUser endpoint; the flaw enables privilege escalation without proper validation. Attackers could, therefore, create privileged application users and elevate their own privileges.
OpenCVE Enrichment