Impact
The vulnerability is a CWE‑200 information disclosure in the Priority Portal Generator add‑on for Priority ERP. An unauthorized actor can access confidential data that is inadvertently exposed by the add‑on, leading to a breach of confidentiality. All versions lacking Priwall v3 are affected. The advisory does not indicate additional privilege escalation, denial of service, or data integrity issues, so the primary impact is the loss of data confidentiality.
Affected Systems
The affected software is the Portal Generator add‑on for Priority ERP, developed by Soft Solutions. No specific versions are enumerated in the advisory, implying that all current releases employing the add‑on may be vulnerable.
Risk and Exploitability
The CVSS score of 8.6 signals a high‑severity issue. The EPSS score is less than 1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not listed in CISA KEV. The likely attack vector is remote, enabled by exposing the Priority ERP infrastructure to the internet. If the system is accessible from outside the corporate network, an attacker could exploit the information disclosure without additional credentials. The CNA’s guidance notes that disabling internet exposure or migrating to Modern Priority Portals mitigates the risk.
OpenCVE Enrichment