Impact
The vulnerability emerges from insecure permissions in the Park Smart Park Management System version 2.0, specifically affecting the RoleController and UserController modules. This is an access control failure (CWE-284) that allows an attacker to use the /system/role/save and /system/user/update endpoints to obtain elevated privileges without proper authorization. Successful exploitation grants full administrative capabilities, enabling modification of system settings, alteration of user accounts, and potential compromise of connected services.
Affected Systems
The affected system is the Park Smart Park Management System version 2.0. No other vendor or product identifiers are specified in the official CNA data.
Risk and Exploitability
Because the flaw is driven solely by configuration and authorization logic, it can be leveraged by any user able to reach the vulnerable endpoints over the network, regardless of local authentication. The CVSS score is 8.8 and the EPSS score is less than 1%, indicating a high severity but low exploitation likelihood. The absence of a KEV listing suggests it has not yet been widely exploited; however, the impact of privilege escalation is severe, and the lack of security controls makes the risk high for any exposed installation. Based on the description, the likely attack vector is a remote attacker interacting with the /system/role/save and /system/user/update endpoints over HTTP.
OpenCVE Enrichment