Impact
The flaw is an improper authentication vulnerability identified as CWE‑287 that allows bypassing the Portal Generator add‑on’s login checks in Priority ERP. An attacker who gains access can impersonate legitimate users, read or modify ERP data, and perform unauthorized actions. The impact is a loss of confidentiality, integrity, and possibly availability of the portal’s data.
Affected Systems
All installations of Priority ERP that use the Portal Generator add‑on and lack Priwall v3 are vulnerable. This includes versions developed by Soft Solutions that have not incorporated the Priwall v3 update.
Risk and Exploitability
The CVSS score of 10 marks this issue as critical. The EPSS score of < 1% suggests that exploitation is unlikely, but the advisory’s recommendation to keep the infrastructure out of reach of the Internet indicates that remote exploitation over public networks is the intended attack vector. An adversary could exploit the authentication bypass remotely to obtain full portal access.
OpenCVE Enrichment