Impact
MicroRealEstate’s Template API does not enforce object‑level access controls, allowing an attacker who can specify a template identifier to retrieve templates belonging to other organizations without proper authorization.
Affected Systems
All installations of MicroRealEstate up to and including the 1.0.0-alpha3 release are affected. The issue is confined to the core product's Template API component used for managing and storing organization‑specific document templates.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is the use of authenticated or unauthenticated HTTP requests to the Template API endpoints, where the attacker supplies a template identifier that belongs to a different organization. By exploiting this flaw, an attacker can retrieve templates that they are not permitted to view. This is strictly a data expose without direct impact on system integrity or availability.
OpenCVE Enrichment