Impact
DeepTutor version 1.4.0 suffers from an authorization bypass in its book confirmation flow. An attacker who is not logged in or who lacks proper privileges can reuse a publicly visible book identifier to submit a confirm‑proposal request for a book that already exists. This allows an unauthorized party to overwrite persisted metadata and the spine content of the book, leading to integrity violations and potential misinformation.
Affected Systems
The vulnerability affects the open‑source DeepTutor platform, specifically version 1.4.0. No other versions or vendor releases are known to be impacted based on the supplied data.
Risk and Exploitability
The exploitability is high because the trigger endpoint is publicly exposed and relies on a single input parameter that can be fabricated. The absence of a CVSS score and available EPSS data means the precise risk magnitude cannot be quantified, but the ability to modify stored content without authentication suggests that the vulnerability could be leveraged by any entity with network access to the service. The defect is not listed in the CISA KEV catalog, yet the impact on data integrity warrants immediate remediation.
OpenCVE Enrichment