Impact
An unsigned client‑side snapshot of view state is restored without an integrity check when a user reconnects. A malicious client can modify the snapshot JSON and return it, causing arbitrary view attributes to be set, such as toggling an admin flag or changing account identifiers and balances. This allows an attacker to gain higher privileges or tamper with business data. The weakness is rooted in the lack of signed snapshots and the mis‑treatment of public view attributes, leading to a classic state injection problem.
Affected Systems
The vulnerability affects djust deployments running versions earlier than 1.0.7 from the djust-org djust product. All releases before 1.0.7 that enable state snapshots are susceptible; the fix begins at 1.0.7 and later.
Risk and Exploitability
With a CVSS score of 8.1 the potential impact is high. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the flaw is not listed in the CISA KEV catalog. The attack vector requires only client‑side manipulation of a page snapshot, meaning an attacker can perform the attack from any browser session that can connect to the vulnerable djust instance. The risk is therefore moderate to high, emphasizing the importance of applying the available patch to eliminate the privilege escalation path.
OpenCVE Enrichment
Github GHSA