Impact
The Priority Portal Generator addon for Priority ERP lacks proper access controls, allowing unauthenticated or unauthorized users to read, modify, or delete ERP data through the web interface. All releases that do not include Priwall v3 are affected. Because the addon does not enforce permission checks, an attacker could exploit the flaw to compromise the confidentiality and integrity of the system.
Affected Systems
The Vista system in question is the Priority Portal Generator addon that integrates with Priority ERP, developed by Soft Solutions. All versions of the addon that do not include Priwall v3 are susceptible. If the portal is publicly reachable, it presents a risk, and any deployment of the addon that remains publicly exposed should be examined.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. The EPSS score is less than 1% (approximately 0.3%), showing a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. This suggests that, although a public exploit may not yet exist, exposed portals still represent a significant risk. The likely attack vector is remote access over the network if the portal is exposed to the internet; an attacker could reach it and bypass the missing access checks. Consequently, the risk remains high if the portal is publicly reachable, even in the absence of an identified exploit. The recommended mitigation is to isolate the portal behind an internal network firewall or to replace it with the vendor‑issued Modern Portals that implement appropriate access controls.
OpenCVE Enrichment