Impact
Based on the description, it is inferred that the vulnerability is a client‑side enforcement of server‑side security flaw in the Priority Portal Generator addon, enabling an attacker to manipulate client‑side checks and submit privileged requests that bypass server‑side controls, thereby granting unauthorized operations and potentially exposing sensitive ERP data, as indicated by the high CVSS score of 9.1.
Affected Systems
Priority:Portal Generator addon to Priority ERP, developed by Soft Solutions. All versions lacking Priwall v3 are susceptible, meaning any deployment of the addon without the latest Priwall restriction layer is affected.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is through the web portal interface, allowing remote attackers with internet access to manipulate client‑side logic. The EPSS score of <1% indicates a low exploitation probability, but the absence of server‑side enforcement and the critical CVSS rating raise the risk. The vulnerability is not listed in the CISA KEV catalog, yet an exposed portal could be a target for attackers seeking privilege escalation.
OpenCVE Enrichment