Impact
The vulnerability originates from a publicly accessible .git directory that exposes repository metadata and source files for the Manacle Technologies multi‑tenant ERP system. An unauthenticated attacker who can reach the exposed directory can download code and configuration artifacts, potentially revealing business logic, credentials, or other sensitive data. The impact is primarily confidentiality loss, with a secondary risk that the exposed source could be further exploited if additional weaknesses exist.
Affected Systems
The affected product is the Manacle Technologies Multi‑tenant ERP System. No specific version information is listed, so the vulnerability applies to any instance where the site has left the .git directory accessible in a web‑servable location.
Risk and Exploitability
With a CVSS score of 9.2 the vulnerability is high severity; the EPSS score is not available, but the lack of authentication requirements combined with direct remote access suggests a high likelihood of exploitation. The vulnerability is not noted in the CISA KEV catalog. Attackers can simply browse to the .git path over HTTP/HTTPS; no additional configuration or privileges are required beyond the web server’s default access.
OpenCVE Enrichment