Impact
The vulnerability arises from improper authorization in the GetAccessible function of PermissionManager.cs. By manipulating input, an attacker can bypass access checks to view or modify resources they should not have permission for, compromising confidentiality and integrity of data managed by FluentCMS. The flaw is available for remote exploitation and has been published for attackers to use.
Affected Systems
FluentCMS releases up to version 0.0.5 are affected. The issue targets the PermissionManager component within the FluentCMS project, and anyone deploying those releases is at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS data is not available, but the exploit is publicly disclosed and can be launched remotely. The vulnerability is not listed in the CISA KEV catalog, yet the availability of a public exploit suggests that exploitation could occur if no mitigation is applied.
OpenCVE Enrichment