Impact
Ech0 components prior to version 4.4.3 lack proper enforcement of access‑token scopes, allowing automatic authorization based solely on an admin role. This results in a privilege‑escalation vulnerability that can expose confidential data and export full database backups. The weakness is classified as improper privilege management (CWE‑285).
Affected Systems
The Ech0 application distributed by lin‑snow is affected. Versions 4.3.4 and older lack the scope checks for privileged admin routes such as /api/inbox, /api/panel/comments, and /api/backup/export. The issue is resolved in version 4.4.3 and later.
Risk and Exploitability
The CVSS score of 7.2 indicates a moderate‑to‑high severity. Exploitation requires an attacker to possess any low‑scope administrative token, which can be obtained if the attacker compromises an existing admin account or captures a token. Once in possession of such a token, the attacker can access privileged endpoints and retrieve sensitive data without additional authentication obstacles. The EPSS score is not available and the vulnerability is not catalogued in CISA KEV, implying that widespread exploitation is not yet confirmed, but the impact remains significant if the conditions are met.
OpenCVE Enrichment