Impact
A broken access control flaw in Idurar IDURAR ERP CRM 4.1.0 permits unauthenticated attackers to download invoice PDF files that contain customer PII. The /download router is mounted without any authentication middleware, making it publicly reachable, and the application allows attackers to enumerate MongoDB ObjectIds to retrieve any invoice. As a result, private customer data can be disclosed to anyone who can reach the system, leading to a breach of confidentiality and potential regulatory violations.
Affected Systems
The vulnerability affects Idurar’s IDURAR ERP CRM version 4.1.0. No other versions are currently known to be impacted.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is clearly remote and requires no authentication. An attacker can simply hit the endpoint, supply an enumerated ObjectId, and obtain a PDF containing PII. Because no additional conditions are needed, the exploitability is straightforward and the potential impact on customer data confidentiality is significant.
OpenCVE Enrichment