Impact
An insecure direct object reference (IDOR) flaw exists in the user settings component of DocuForm GmbH Client version 11.11c. Based on the description, it is inferred that an attacker would need to access the client’s UI or API to read, modify, or execute code in the context of other users’ accounts, which would compromise confidentiality, integrity, and availability for those accounts.
Affected Systems
DocuForm GmbH Client, version 11.11c.
Risk and Exploitability
The EPSS score is < 1%, indicating a low exploitation probability, though it is not listed in the CISA KEV catalog. The CVSS score of 8 high severity issue. The flaw can be exercised remotely through the user settings component, and it is inferred that a remote attacker could exploit this vulnerability via the client interface or internal API if they obtain authenticated access, but the CVE description does not explicitly identify a specific web interface or API endpoint. Given the absence of a public exploit or mitigated version, the risk remains significant until a patched version is deployed.
OpenCVE Enrichment