Impact
Caddy Proxy Manager enabled email and password self‑registration by default in its sign‑up API, allowing any unauthenticated remote actor to create an account with the default "user" role. The "user" role has no privileges to view or edit proxy configurations, so the direct impact is limited to the ability to create low‑privilege accounts but it can serve as an entry point for further attacks or testing. The vulnerability is a configuration flaw that permits account creation without administrator approval.
Affected Systems
The issue affects the Caddy Proxy Manager application from vendor fuomag9. Any installation running an unpatched version older than 1.5.1 is susceptible. System administrators should verify that the product version is at least 1.5.1 or that the configuration has been hardened to disable self‑registration.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate impact and a low complexity of exploitation. The EPSS score of less than 1% indicates a very low current probability of exploitation. The vulnerability is not listed in CISA KEV and is not a known widely‑exploited weakness. The attack vector is likely remote and unauthenticated, requiring only HTTP access to the sign‑up endpoint.
OpenCVE Enrichment