Impact
The flaw allows an attacker to craft a request to the User, causing the server to apply the update operation on any arbitrary user account. The exploitation can be performed remotely over the network and does not require elevated privileges; an authenticated user can simply change the userid they send, gaining unauthorized modification rights over other users. This results in a breach of data integrity and potentially confidentiality for affected accounts.
Affected Systems
The vulnerability is present in the open‑source E-commerce-project-springBoot repository maintained by jaygajera17. No specific version range is published because the project affected code base exists up to commit 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is less than 1%, and the issue is not listed in CISA’s KEV catalog. The exploit is publicly available and can be carried out remotely via the web interface, subject to the attacker discovering a valid userid value. Because the vulnerability is an IDOR that requires only an HTTP request, the likelihood of exploitation is moderate, particularly in environments where user enumeration is possible.
OpenCVE Enrichment