Impact
Unverified remote attackers can exploit a missing authentication flaw in CAYIN CMS-WS and CMS-SE to retrieve lists of media files. This vulnerability allows an attacker to obtain potentially sensitive information about the file structure and contents, constituting partial information disclosure. The weakness is a classic Missing Authentication issue, classified as CWE‑306.
Affected Systems
The flaw afflicts CAYIN Technology’s CAYIN CMS‑WS and CAYIN CMS‑SE products. All releases of CMS‑WS prior to 1.0.26198 and all releases of CMS‑SE prior to 11.0.26198 are vulnerable. Updating to the specified or later versions mitigates the issue.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. The EPSS score is not published, and the vulnerability is not listed in the CISA KEV catalog, suggesting no immediate known widespread exploitation. The attack vector is remote; unauthenticated users can reach the affected endpoints over HTTP/HTTPS. While the flaw does not permit code execution, the disclosure of media file names can aid in planning further attacks against the system.
OpenCVE Enrichment