Impact
The flaw stems from inserting sensitive information into outbound data streams and from insufficient enforcement of access control lists. An attacker can embed confidential data into responses transmitted by Proliz's OBS and can access privileged functions that should be protected, resulting in a direct breach of confidentiality and the potential bypass of authorization controls.
Affected Systems
Proliz Software Ltd. Co. Proliz's OBS versions older than 3.6.0 are affected.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. Based on the description, it is inferred that an attacker can trigger the flaw by sending crafted requests over the network, implying a remote attack vector that does not require user interaction. The vulnerability is not listed in CISA’s KEV catalog, but its combination of high impact and potential remote reach warrants timely mitigation.
OpenCVE Enrichment