Impact
The vulnerability resides in DeepTutor 1.4.0's TutorBotManager.write_bot_file function, which allows a remote user to supply a user‑controlled object identifier. This leads to an authorization bypass that permits enumeration of bot IDs and overwriting of another bot's whitelisted control files via the HTTP tutorbot file route. As a result, an attacker can modify privileged configuration files that govern bot behavior, potentially enabling execution of arbitrary actions or unauthorized bot commands.
Affected Systems
Affected is DeepTutor version 1.4.0. No additional vendor or product versions are documented in the CVE.
Risk and Exploitability
The flaw can be exploited remotely over HTTP without authentication, enabling malicious enumeration and alteration of protected files. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. A CVSS score has not been published, so the precise severity cannot be quantified from the available data. Nonetheless, the ability to overwrite whitelisted control files represents a significant risk to integrity and operational control of the system.
OpenCVE Enrichment