Impact
MicroRealEstate fails to manage token state, allowing attackers to bypass authentication by brute‑forcing One‑Time Passwords (OTP). The flaw constitutes an authentication bypass (CWE‑288) that permits an attacker to log in as any user without valid credentials. The description confirms that an attacker can become any user; it is inferred that this would grant the attacker all privileges associated with that user account, effectively enabling unauthorized access beyond the intended user scope.
Affected Systems
MicroRealEstate software versions up to and including 1.0.0‑alpha3 are affected. All deployments of the product are vulnerable unless a newer release that implements proper token state management is in use.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity; an EPSS score of < 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Remote attackers can exploit the weakness by targeting the web interface or API endpoint that verifies OTPs, and because no token state is checked they can iteratively guess or brute‑force OTP values to gain authenticated sessions as any user. The likely attack vector is inferred from the description, which mentions bypassing authentication via OTP.
OpenCVE Enrichment