Impact
The vulnerability in the Journey Photo Proxy component of liketrek TREK allows an attacker to manipulate the validateShareTokenForAsset function, causing the system to fail to enforce proper authorization. This weakness is an example of improper authorization (CWE‑285) and improper use of shared resources (CWE‑863). Malicious actors can obtain access to assets or services that should be restricted, potentially exposing sensitive media or personal data.
Affected Systems
This flaw exists in all installations of liketrek TREK versions up through 3.0.22. Version 3.1.0 incorporates a fix and is not affected. Users running 3.0.22 or earlier are at risk.
Risk and Exploitability
The CVSS score of 6.3 classifies this as a moderate severity issue. Exploitation can be performed remotely, and the description notes high complexity and difficulty, indicating that a skilled attacker must carefully construct the exploit. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or no known active exploitation in the wild.
OpenCVE Enrichment