Impact
A vulnerability was discovered in SiteServer SSCMS 7.4.0 that allows an attacker to manipulate the SecurityKey argument within the Agent Installation Workflow component. By tampering with this argument, the system fails to enforce proper access controls, enabling an attacker to gain unauthorized privileges or execute actions that should be restricted. The weakness aligns with CWE-266 and CWE-284, both related to improper use of privileged permissions and insufficient access controls. This flaw permits remote exploitation, meaning that an attacker can trigger the vulnerability over the network without needing local access.
Affected Systems
The affected product is SiteServer SSCMS, specifically version 7.4.0. The vulnerability exists in the Agent Installation Workflow component of this version. Users running 7.4.0 are potentially at risk. No other versions are specifically identified, but the impact is limited to the stated iteration.
Risk and Exploitability
The CVSS score is 2.3, indicating low overall severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. While the attack has high complexity and is considered difficult, the exploit remains possible from a remote location. The lack of a public patch and the low CVSS suggest that the risk is modest, but the possibility of unauthorized access warrants monitoring and mitigative action.
OpenCVE Enrichment