Impact
The vulnerability is an insecure direct object reference that allows an unauthenticated remote attacker to manipulate a request parameter on an API endpoint. By exploiting this flaw the attacker can read sensitive data that belongs to other users within the multi‑tenant ERP system. The flaw arises from improper authentication and authorization checks, leading to a confidentiality breach.
Affected Systems
Affected systems consist of the multi‑tenant Enterprise Resource Planning application produced by Manacle Technologies. Specific version details have not been disclosed, so any deployment of that ERP platform should be evaluated.
Risk and Exploitability
The flaw carries a CVSS score of 9.2, indicating a high severity and potential for significant impact. No EPSS score is available, but the vulnerability has not been reported in the CISA KEV catalog. The attack requires no privileged user credentials and can be carried out remotely by submitting a crafted request to the API endpoint, making it readily exploitable for a determined attacker.
OpenCVE Enrichment