Impact
The vulnerability is an incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0, allowing unauthenticated attackers to access all seller management interfaces. Attackers can list products and orders, place products on sale or off sale, finish or cancel orders, and modify categories without authentication. This flaw is a classic authentication bypass, categorized as an Access Control vulnerability.
Affected Systems
springboot-project v1.0.0. No specific vendor or product enumeration is available, so any deployment of this version is potentially affected.
Risk and Exploitability
The flaw permits full non‑authenticated access to privileged seller functions, a high‑impact misuse of authority. Because the component lacks proper authentication checks, any user who can reach the application endpoints can exploit it. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but the absence of controls suggests a high likelihood of exploitation in environments where network access to the application is not otherwise restricted.
OpenCVE Enrichment