Impact
SysPass through version 3.2.11 suffers from an insecure direct object reference that allows any authenticated user to access, view, delete, upload, or list account file attachments for accounts they should not have permission to access. By supplying arbitrary numeric file identifiers to the AccountFileController endpoints, an attacker can enumerate and manipulate any attachment stored in the vault, effectively bypassing all ACL checks and gaining full access to confidential data attached to other users' accounts.
Affected Systems
The vulnerability affects Nuxsmin’s SysPass product, specifically all releases up to and including version 3.2.11. Any deployment of SysPass within this version range is at risk, regardless of how the application is hosted or accessed.
Risk and Exploitability
The CVSS score of 8.6 indicates a high level of severity. The EPSS score of < 1% reflects a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw requires authentication, the attacker must first compromise valid credentials. Once authenticated, the attacker can remotely request the vulnerable endpoints over the network to retrieve or manipulate files, thereby achieving a complete breach of data confidentiality.
OpenCVE Enrichment