Impact
Ech0 before version 4.4.3 fails to enforce scope‑based authorization on nine protected comment panel admin endpoints. As a result, authentication tokens that carry only minimal scopes are incorrectly allowed to list, approve, reject, delete comments, and alter comment system settings. This weakness can compromise the integrity and confidentiality of user‑generated content and the overall moderation workflow. The weakness is classified as CWE‑862, indicating an authorization defect.
Affected Systems
The vulnerability affects the Ech0 application developed by lin‑snow. All releases prior to 4.4.3 are impacted. No specific patch version is listed in the input, so any version earlier than 4.4.3 must be considered at risk.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector involves an attacker who has obtained a legitimate access token with limited scopes; such a token can be used to make authenticated requests to the unprotected admin endpoints, achieving privilege escalation within the comment subsystem. The ability to tamper with moderation settings and comment data represents a significant risk if the application is publicly exposed.
OpenCVE Enrichment