Impact
The vulnerability in x-ui allows an authenticated user to alter inbound proxy configurations belonging to other users. The flaw resides in the update path that neglects to confirm the ownership of the target configuration when a request references its identifier. Consequently, a malicious actor can change remarks, ports, protocols, settings, enabled state, expiry time, and traffic quota for other accounts, potentially impacting confidentiality, integrity, and availability of those users’ network traffic.
Affected Systems
x-ui version 0.3.2 is affected. No other product or vendor versions are listed.
Risk and Exploitability
Because the exploit requires only authenticated access and the attacker can target any inbound proxy configuration by supplying the desired identifier, the risk is high for any environment where cross‑user modification is not otherwise constrained. No CVSS score is provided and the EPSS score is unavailable, but the vulnerability is listed as not in KEV, indicating no current widespread exploitation. However, the straightforward nature of the request suggests that any compromised or poorly secured instance of x-ui could be abused for horizontal privilege escalation.
OpenCVE Enrichment