Impact
An insecure direct object reference flaw in the user settings component of DocuForm GmbH Client 11.11c allows a remote attacker to execute arbitrary code and access or alter other users’ sensitive data. The vulnerability stems from insufficient validation of object identifiers, enabling unauthorized actions via the client’s UI or internal API calls. When exploited, it compromises confidentiality, integrity, and availability for the affected accounts.
Affected Systems
DocuForm GmbH Client, version 11.11c, is the only version identified as vulnerable. The flaw specifically targets the user settings component within this product.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, whereas the EPSS score of less than 1% suggests a low likelihood of active exploitation. The vulnerability is not listed in CISA KEV, which further reduces concern for widespread current exploitation. The description of the vulnerability states remote exploitation via the user settings component, but no public web interface or API is mentioned; thus the attack vector is inferred to be through the client’s UI or an internal API, likely needing authenticated access. Given the absence of publicly available exploits and a low EPSS, the immediate risk is limited but the potential impact warrants swift remediation.
OpenCVE Enrichment