Impact
A missing authorization check in the Module::settingsForm function of Xibo CMS allows an existing authorized user to view super-admin-restricted module settings and leak the complete module entity. The flaw does not permit modification of the settings, but it exposes sensitive configuration data that should remain confidential. This is an example of an information disclosure vulnerability classified as Missing Authorization (CWE-862).
Affected Systems
All installations of the Xibo CMS product from vendor xibosignage running any version prior to 4.4.3 are affected. The vulnerability is tied to the Module View feature, which is typically enabled only for users with administrative privileges.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and no EPSS score is available at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user who has been granted access to the Module View functionality; exploitation requires no special privileges beyond those already assigned. Once the flaw is exploited, an attacker can obtain detailed module settings but cannot alter them. Given that privileged accounts are usually constrained, the overall impact is limited to confidentiality exposure of module configuration rather than privilege escalation or system takeover. Nonetheless, remediation is recommended to prevent potential data leakage.
OpenCVE Enrichment