Impact
The vulnerability is a broken access control flaw that enables authenticated attackers with Agent-level privileges to alter the support agent assignment field on any ticket they can view, bypassing intended authorization checks. By adding or removing any user, including Superadmin accounts, an attacker can re‑assign tickets, potentially redirecting work or gaining unauthorized visibility. This flaw, identified as CWE-862, undermines the integrity of ticket ownership and can facilitate privilege escalation or data exposure.
Affected Systems
Ultimate Fosters Perfect Support Ticketing & Document Management System version 1.7 is affected. Users with Agent‑level roles who can log in to the system may exploit this issue by changing ticket assignments that they are authorized to view.
Risk and Exploitability
The CVSS score of 5.3 marks a medium severity, and the EPSS score of <1% indicates a very low, yet non‑zero, likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires that the attacker be an authenticated user with Agent privileges; they can then manipulate the assignment field on any accessible ticket. Based on the description, it is inferred that the attack vector is an authenticated in‑application request that bypasses role‑based checks.
OpenCVE Enrichment