Impact
The AuthorizeActionFilter in DotVVM fails to enforce any authorization because its implementations of the action filter interfaces simply complete immediately without invoking the necessary checks. As a result, protected commands, view models, and presenters can be executed by any caller who sends a request, effectively bypassing access control. This flaw is a Missing Authorization weakness, identified as CWE‑862, and can expose sensitive data or allow unintended actions.
Affected Systems
Applications built with DotVVM that use the AuthorizeActionFilter prior to patched releases—v4.2.11, v4.3.15, or v5.0.0‑preview09‑final—are affected. Deployments that rely on this filter for securing commands, view models, or presenters without overriding it with proper authorization logic are vulnerable.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger protected functionality simply by sending a request that activates a command, view model, or presenter guarded by this filter, without requiring any special bypass technique. The low bar to exploitation means that any user who can interact with the application—authorized or otherwise—may be able to exercise privileged actions.
OpenCVE Enrichment