Impact
The vulnerability stems from insecure permissions within the Park Smart Park Management System v.2.0, specifically in the RoleController and UserController components. Remote actors can exploit the /system/role/save and /system/user/update endpoints to gain elevated privileges without proper authorization checks. Successful exploitation yields full administrative control, enabling the attacker to alter system configurations, manipulate user accounts, and potentially compromise other connected services.
Affected Systems
The affected system is the Park Smart Park Management System version 2.0. No other vendor or product identifiers are specified in the official CNA data.
Risk and Exploitability
Because the flaw is driven solely by configuration and authorization logic, it can be leveraged by any user able to reach the vulnerable endpoints over the network, regardless of local authentication. With no EPSS score available, the exact exploitation probability is unknown, but the absence of a KEV listing suggests it has not yet been widely exploited; however, the impact of privilege escalation is severe, and the lack of security controls makes the risk high for any exposed installation.
OpenCVE Enrichment