Impact
Observable Discrepancy in the Priority Portal Generator addon to Priority ERP allows external observers to detect unintended differences in portal responses. This behavior, classified as CWE‑203, can reveal system or configuration details and result in information disclosure. Although it does not facilitate direct code execution, the ability to gather reconnaissance data about the underlying infrastructure can support subsequent attacks.
Affected Systems
All releases of the Priority Portal Generator addon to Priority ERP distributed by Soft Solutions that do not include Priwall v3 are affected. These add‑ons are typically deployed as part of the Priority ERP suite and may be reachable from the public internet or from internal networks if not properly isolated.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the vulnerability can be triggered by sending requests to the portal’s publicly exposed endpoints when the addon is reachable from outside the secure network. Attackers could use the observed differences to gather reconnaissance data, but the lack of a public exploit and low EPSS mitigate immediate risk. The recommended mitigation involves restricting internet exposure or upgrading to Modern Priority Portals, which removes the observable discrepancy.
OpenCVE Enrichment