Impact
The vulnerability resides in the top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie function and allows an attacker to manipulate cookie data to bypass authentication. This improper authentication is a classic authorization flaw, classified as CWE-287, and grants unauthorized actors access to user accounts or restricted functions, compromising confidentiality and integrity of the system.
Affected Systems
Affected systems are the ChangeWeDer CRM product. No specific release numbers are provided; the issue exists in builds up to commit c07bd4c97141521af6475034bc58523beed51bbd. Because the project uses continuous delivery with rolling releases, any active deployment may be vulnerable until a fix is released.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability can be triggered remotely via crafted cookie data; no local or privileged access is required. The vulnerability is not listed in CISA KEV, so no immediate exploit evidence exists, but monitoring for suspicious authentication attempts remains prudent.
OpenCVE Enrichment