Impact
The vulnerability in Priority’s Portal Generator addon to Priority ERP, developed by Soft Solutions, allows an unauthorized actor to access sensitive and private personal data stored in the ERP system. This flaw is a classic information disclosure vulnerability, classified as CWE‑200, exposing confidential data and private personal information.
Affected Systems
Affected systems are installations of Priority ERP that use the Portal Generator addon, developed by Soft Solutions. The addon must be present; specific versions are not listed in the advisory, so all deployed instances of the portal generator are vulnerable unless configured otherwise.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. The EPSS score is 0.00303, indicating a very low but nonzero likelihood of exploitation, but the vulnerability is still considered likely to be exploited if the addon is reachable from the internet. According to the CNA, the attacker could retrieve sensitive data via the portal’s web interface, assuming no additional access controls are in place. The vulnerability is not listed in the CISA KEV catalog, however precautionary measures remain essential.
OpenCVE Enrichment