Impact
The vulnerability in dibo-software’s diboot 3.8.0 allows attackers to manipulate the /api/ai-session/ endpoint, resulting in an authorization bypass that can grant unauthorized access to protected resources. This flaw stems from improper access control (CWE-285) and the improper handling of sensitive data (CWE-639). The result is that anyone with the correct endpoint can access AI session data without proper credentials.
Affected Systems
The flaw affects dibo-software’s diboot product, specifically version 3.8.0. No other versions are listed as impacted, and the disclosed vulnerability targets the web interface exposing /api/ai-session/.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the attack can be launched remotely. EPSS data is not available, yet the exploit has been publicly disclosed and may be used by adversaries. Although not listed in CISA’s KEV catalog, the remote nature and lack of a defensive measure make the vulnerability potentially exploitable.
OpenCVE Enrichment