Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass intended access controls in Universal Software Inc. FlexCity. This weakness can enable a user to acquire higher level privileges or access restricted resources (CWE‑862). The impact is a privilege‑escalation problem that threatens the confidentiality and integrity of the system and its data.
Affected Systems
Version 5.536.0 through just before 5.542.0 of Universal Software Inc. FlexCity are affected. No other editions or earlier releases are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.5 categorizes the flaw as moderate to high severity, but the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The flaw is not included in the CISA KEV catalog. The attack vector is inferred to be through a web or management interface that is misconfigured or uses default credentials, permitting an attacker to elevate privileges or bypass restricted functionality.
OpenCVE Enrichment