Impact
The Ech0 application versions prior to 4.7.3 contain an authentication bypass flaw in the PUT /api/echo/like/:id endpoint. Attackers can issue unauthenticated requests to increment the fav_count field for any known echo, allowing arbitrary inflation of engagement metrics. This flaw compromises the integrity of engagement data and distorts social ranking mechanisms used by the platform.
Affected Systems
All deployments of Ech0 with a version number less than 4.7.3 are affected. The vulnerability is present in the Ech0 application itself, regardless of the underlying operating system or environment; any installation using an unpatched version is at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating moderate severity if exploited. The EPSS score is not available, making the exploitation probability uncertain, and it is not listed in the CISA KEV catalog. An attacker only needs to send unauthenticated HTTP requests to a live Ech0 instance over the network; no authentication or rate limiting is applied, so repeated requests can quickly inflate metrics.
OpenCVE Enrichment