Impact
The vulnerability is a missing authentication flaw in the Portal Generator addon to Priority ERP, which allows unauthenticated users to execute critical functions and access potentially sensitive data. This CWE‑306 weakness results in a high CVSS score of 9.3 and is considered a serious authentication bypass.
Affected Systems
The affected product is the Portal Generator addon for Priority ERP, developed by Soft Solutions. All versions of the addon that do not incorporate Priwall v3 are vulnerable; no further version specificity is listed in the advisory.
Risk and Exploitability
Because authentication is omitted, anyone able to reach the Portal Generator endpoint can exploit the flaw. The EPSS score of 0.00292 (0.292%) indicates a very low probability of exploitation in the near term, yet the high CVSS score exposes a severe risk if the addon is reachable from the Internet. The vulnerability is not listed in the CISA KEV catalog and no known exploits have been reported.
OpenCVE Enrichment