Impact
The vulnerability involves the insertion of sensitive information into data sent by the IKAS Technology Inc. E‑Commerce platform. This flaw allows an attacker to retrieve embedded sensitive data, effectively exposing confidential information. The weakness is a Sensitive Data Exposure, classified as CWE‑201, and can potentially compromise the confidentiality of user credentials and other private data.
Affected Systems
IKAS Technology Inc. E‑Commerce, versions through 03‑06‑2026
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact. The EPSS score of less than 1% shows a very low likelihood of exploitation, and the vulnerability is not included in the CISA KEV catalog. Based on the description, the likely attack vector is remote, involving crafted HTTP requests that trigger the out‑bound data path. No additional network or privilege prerequisites are stated, suggesting the flaw can be leveraged from any networked location that can reach the application.
OpenCVE Enrichment