Impact
The vulnerability is a broken access control flaw in the tts‑be backend, which permits unauthenticated requests to several API endpoints such as "/api/student/{id}/photo" and "/api/course_unit/{id}/exchange/metadata". By chaining these endpoints, a remote attacker can treat the service as an open proxy, circumventing the intended authorization checks and extracting personally identifiable information from upstream university systems, including full names, student IDs, class schedules, and photos. The flaw enables an attacker to read data that should be protected, leading to a confidentiality breach.
Affected Systems
The affected product is NIAEFEUP’s tts‑be timetable‑selection backend. Any deployment of tts‑be versions earlier than 2.1.0 is vulnerable. The issue has been remedied in version 2.1.0, which enforces proper access controls on all exposed APIs.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability presents a moderate‑to‑high severity risk. The EPSS score of less than 1% indicates a low probability of exploitation under current conditions, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, relying on an attacker sending HTTP requests to the exposed endpoints over the internet or an insecure internal network. If the service is publicly accessible, the impact could rapidly spread, as attackers can repeatedly enumerate user identities and associated data, exploiting the lack of authentication and authorization controls.
OpenCVE Enrichment