Impact
BurgerEditor versions 3.0.0 through 3.4.0 contain an authorization bypass that enables an attacker who can log in to the application to alter page content. The flaw is a form of unauthorized access to privileged functions, allowing malicious modification of information presented to users. It arises from improper validation of a user‑controlled key during authorization checks.
Affected Systems
Affected systems include D‑ZERO CO.,LTD.'s BurgerEditor product, specifically versions 3.0.0 to 3.4.0.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. Because EPSS is not available and the vulnerability is not listed in CISA KEV, the exploitation likelihood is moderate. The attack vector is likely internal, requiring an authenticated user to supply the key. An attacker could use the key to bypass authorization and modify resources. No vendor‑supplied patches or workarounds are currently disclosed.
OpenCVE Enrichment