Impact
A public API endpoint of the Superior Court of California Hearing Reminder Service returns court reminder records that may include sensitive information without requiring authentication. The weakness is a missing authentication check, which is classified as CWE‑306. The impact is a moderate level of confidential data exposure; an attacker could retrieve personal details or case information that should be protected.
Affected Systems
The vulnerability affects the Superior Court of California, County of Los Angeles Hearing Reminder Service. No specific product versions are listed in the available data, and the location of the exposed API is https://www.hrs.courts.ca.gov.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS score is <1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is an unauthenticated web API accessible to anyone on the public internet.
OpenCVE Enrichment