Impact
The vulnerability in AVESİS is an external control of an assumed‑immutable web parameter (CWE‑472). The likely attack vector is manipulation of the web parameters. Because the system trusts that certain query or form parameters will not be altered by a client, an attacker can manipulate those values to reach functionality that should be secured behind access control lists. In practice this means that an unauthorized user could invoke protected actions or access data that they are not permitted to view, which could be used for privilege escalation or data exposure. The CVSS score of 5.3 indicates a moderate risk, and the knowledge of the specific parameter and ACL details is not disclosed.
Affected Systems
ABIS Technology Ltd. Co.'s AVESİS product prior to the release dated 202606251646 is affected. Any deployment of the software older than that build, regardless of configuration, is susceptible to the flaw because the version check was introduced only in that release to enforce proper parameter immutability.
Risk and Exploitability
The exploitation probability is very low, as the EPSS score is below 1%, and the vulnerability is not included in the CISA KEV catalog, implying no publicly documented exploitation. Based on the description, it is inferred that the attacker must successfully identify the vulnerable parameter to craft the request. Attackers would need to identify the specific web parameter that is incorrectly considered immutable and submit crafted requests to bypass ACL checks, which requires a basic level of per‑application knowledge but no special privileges. Given the moderate CVSS score, the impact of a successful attack remains significant, but the low likelihood and lack of active exploitation reduce the overall threat posture.
OpenCVE Enrichment