Impact
The vulnerability is a missing authentication requirement in the web.xml configuration of the Admin Console and DPO Compliance Console of tsi-dpdp-cms, representing a CWE-287 and CWE-306 weakness. An attacker can craft requests that bypass user validation and gain unauthorized access to the console.
Affected Systems
Version 0.5.0 and earlier of tsi-coop’s tsi-dpdp-cms are affected. The problematic component is the Admin Console/DPO Compliance Console module. An upgrade to version 0.5.1 eliminates the missing authentication configuration and resolves the issue.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS scores are not provided, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely via crafted HTTP requests, and it has been publicly disclosed, allowing potential exploitation. Because the administrator interface is exposed over the network, the attack vector can be ground up from any machine that can reach the exposed port unless additional network controls are in place.
OpenCVE Enrichment