Impact
A flaw in the core/stats.py component of jofpin trape 1.0.0 allows an attacker to call the login endpoint without providing any authentication credentials. The missing authentication check means that an unauthenticated user can access the statistics route remotely, which could expose sensitive usage data or other internal information. The attack requires only a standard HTTP request and is widely available through public code examples.
Affected Systems
The vulnerability is confirmed only for the jofpin trape product, version 1.0.0, as noted by the CNA. No other versions or product variants are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. No EPSS value is available, and the issue is not referenced in CISA’s KEV catalog, but the ability to bypass authentication remotely combined with the publicly available exploit makes it a tangible threat. Until an official fix is released, the risk remains high for any installation that exposes the vulnerable endpoint to untrusted networks.
OpenCVE Enrichment