Impact
A flaw in jofpin Trape’s core/user.py allows an attacker to modify the vId or id argument and bypass the authorization checks, effectively granting unauthorized access to protected resources. The weakness is a classic Authorization Bypass (CWE‑285) and relates to poor authentication‐to‐authorization correlation (CWE‑639). The impact is the ability for a remote actor to act as an arbitrary user without authenticating, potentially exposing sensitive data or performing privileged operations.
Affected Systems
The vulnerability affects the jofpin Trape application, specifically version 2.0. No other versions or additional products are listed as impacted.
Risk and Exploitability
With a CVSS score of 6.9, the severity is moderate, yet the exploit is publicly available and can be delivered remotely by manipulating query parameters. The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, but the existence of a public exploit increases the likelihood of real‑world attacks. Administrators should treat the exposure as a significant risk to confidentiality and integrity of user data.
OpenCVE Enrichment