Impact
An authorization bypass flaw exists that allows an attacker who can log in to ShizenBox2 to change another user’s password by supplying a user-controlled key. The vulnerability is a privilege escalation within the application, enabling an attacker to impersonate other users or initiate further attacks from that account.
Affected Systems
The affected system is the ShizenBox2 edge‑app from Shizen Connect Inc. No specific version information is supplied in the CVE entry, so all released builds of ShizenBox2 are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, but the lack of a KEV listing suggests no publicly known exploit at the time of reporting. Exploitation requires the attacker to possess valid credentials to log in to the product; once logged in, the flaw can be abused without additional network access. The risk is considered high for environments where account isolation is critical.
OpenCVE Enrichment