Impact
MicroRealEstate implements object‑level access controls that are broken (CWE‑1241) and uses a deterministic pattern for ID generation can guess or enumerate the identifiers for documents uploaded by landlords or tenants and fetch them without authorization. This results in the disclosure of confidential tenant and landlord documents, potentially violating privacy regulations and compromising sensitive information.
Affected Systems
The vulnerability is present in MicroRealEstate versions up to and including 1.0.0-alpha3. Any installation that has not been upgraded beyond that release is affected, especially deployments that expose the web interface allowing direct access to document URLs.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The EPSS score of < 1% indicates a very low probability of exploitation; however the web interface is reachable. Likely attack vector is through the web interface enabling direct access to document URLs, and based on the description it is inferred that the deterministic IDs enable the attacker to fetch documents. The vulnerability is not listed in the CISA KEV catalog, so no publicly known active exploitation exists at this time.
OpenCVE Enrichment