Impact
Wallos generates an OIDC state nonce during login but never checks the state returned by the OIDC provider. An attacker who can lure a victim to a crafted URL can cause Wallos to exchange the victim’s authorization code and log the victim into the attacker’s account instead. The flaw enables an attacker to hijack a victim’s session and gain full access to that account, compromising confidentiality and integrity of the victim’s subscription data.
Affected Systems
The vulnerability affects Version 4.9.3 and earlier of the open‑source personal subscription tracker Wallos, developed by ellite. Any deployment of these versions that has OIDC authentication enabled is impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No exploit code is required; the flaw is triggered by a crafted URL and does not depend on local privileges or pre‑existing authentication. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Nevertheless, the impact of a successful CSRF attack is substantial, allowing full account takeover by remote adversaries.
OpenCVE Enrichment