Impact
MicroRealEstate’s PDF generation feature does not enforce object‑level security checks, allowing an attacker to supply an object identifier that is returned in the objects that should remain hidden being exposed, thereby violating data confidentiality. The weakness is a classic case of CWE‑639, broken object‑level access control.
Affected Systems
The vulnerability affects all MicroRealEstate releases up to and including 1.0.0‑alpha3. Any deployment of those or work‑around is applied.
Risk and Exploitability
The CVSS score of 7.1 suggests high severity, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is the network‑accessible PDF generation endpoint; an attacker can send a crafted HTTP request containing an object identifier and retrieve a PDF that contains unauthorized confidential data.
OpenCVE Enrichment