Impact
An insecure direct object reference vulnerability exists in the api_vedo/chat endpoint of Bottinelli Informatica Vedo Suite. The utente_chat parameter can be manipulated by an unauthenticated remote attacker, allowing the retrieval of sensitive data that the attacker should not be able to see. This attack transmits data that the attacker is not authorized to access, exposing confidential information and undermining the confidentiality of the system. The weakness aligns with CWE-639, Authorization Bypass through User‑Controlled Key.
Affected Systems
The CVE record specifically lists Bottinelli Informatica Vedo Suite version 1.2.5 as affected. No other products or versions are mentioned, indicating the issue is limited to this release.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation. The CVSS score of 7.5 classifies this vulnerability as high severity, reflecting the potential for unauthorized data access. The KEV designation indicates that this vulnerability is not listed in CISA's KEV catalog, leaving precise exploitation likelihood uncertain. However, the vulnerability can be leveraged remotely without authentication, provided the api_vedo/chat endpoint is exposed to an attacker. Attackers can construct a request targeting the endpoint with a crafted utente_chat value, likely pulling the requested data from the server. With the information disclosed, the impact is significant for any environment running the vulnerable version and reachable from untrusted networks.
OpenCVE Enrichment