Impact
The vulnerability stems from hard‑coded credentials embedded in the Priority:Portal Generator add‑on for Priority ERP, developed by Soft Solutions. These credentials allow an attacker to bypass authentication, exposing sensitive information to unauthorized actors and enabling potential administrative control over the system. The flaw also represents an improper access control weakness, allowing privileged actions without proper authorization checks.
Affected Systems
The affected component is the Priority:Portal Generator add‑on for the Priority ERP platform, developed by Soft Solutions. All releases that lack Priwall v3 are vulnerable; any environment that runs such a version is exposed if the add‑on is accessible.
Risk and Exploitability
The CVSS score of 9.3 categorises the issue as critical. The EPSS score of < 1 % indicates a very low but non‑zero probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can target any publicly exposed Priority infrastructure that hosts the add‑on, using the hard‑coded credentials to gain privileged access and potentially move laterally within the affected system.
OpenCVE Enrichment