Impact
The flaw exists in tsi-coop tsi‑dpdp‑cms versions up to 0.5.0. It causes security to be enforced only on the client side, while the server does not perform proper authentication checks. As a result, an attacker can bypass intended security controls and gain unauthorized access to protected resources or administrative functions. The weakness is classified as CWE‑602.
Affected Systems
The component affected is tsi‑coop tsi‑dpdp‑cms. Versions up to and including 0.5.0 contain the flaw. Upgrading to version 0.5.1 eliminates the vulnerability, as documented in the project’s release notes.
Risk and Exploitability
The CVSS base score is 6.9, indicating moderate severity. The attack can be launched remotely through crafted HTTP requests, and a publicly available exploit has been released, making it a realistic threat for exposed deployments. The vulnerability is not listed in the CISA KEV catalog and no EPSS score is provided, but the combination of a remote attack vector with client‑side enforcement creates a low‑barrier bypass path for attackers.
OpenCVE Enrichment