Impact
Improper Access Control in the Priority Portal Generator add‑on to Priority ERP (developed by Soft Solutions) allows an attacker to bypass authorization checks and access protected resources. All versions without Priwall v3 are vulnerable. This flaw can lead to unauthorized data exposure or modification, compromising the confidentiality and integrity of ERP data.
Affected Systems
Affected systems include the Priority ERP Portal Generator add‑on by Soft Solutions, all versions lacking Priwall v3, which is part of the Priority ERP platform. Administrators and users are impacted if the standard configuration exposes the portal to the internet.
Risk and Exploitability
The CVSS score of 8.2 marks this as high severity. The EPSS score is 0.00244, indicating a low probability of exploitation. KEV lists it as not included. The likely attack vector is remote over the internet, as the recommendation explicitly warns against exposing the infrastructure. An attacker can exploit the flaw if the portal is accessible from outside, potentially bypassing authentication or authorization controls.
OpenCVE Enrichment