Impact
The vulnerability is a missing authorization flaw in the ExAutenticacaoController.autenticar function. By manipulating the cod/jwt argument, an attacker can bypass normal access controls and obtain unauthorized privileges. The weakness is classified as CWE-862 (Missing Authorization) and CWE-863 (Failed or Insufficient Authorization). The effect is that sensitive data or protected operations can be accessed by unauthenticated or improperly authorized users.
Affected Systems
The affected product is projeto‑siga Siga software. Versions up to 11.0.2.10, 11.0.2.13, and 11.1.1 are vulnerable. Any deployment of essas versões without a subsequent update is at risk.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate severity. The vulnerability can be leveraged remotely by crafting a request that manipulates the cod/jwt parameter, though the EPSS is not reported. It is not currently listed in the CISA KEV catalog. If unpatched, the risk is that an attacker could gain unauthorized access to protected resources, potentially leading to data exposure or unauthorized actions.
OpenCVE Enrichment