Impact
The vulnerability arises from a missing authorization check in the index function of UserController.java, allowing an attacker to invoke the endpoint without proper privileges. This weakness permits unauthenticated or improperly authenticated users to access or manipulate resources that should be protected, representing missing authorization and missing access control errors (CWE-862, CWE-863). The flaw could enable attackers to read sensitive data or perform operations beyond intended permissions.
Affected Systems
The flaw affects the ChangeWeDer CRM application (product ChangeWeDer:crm). All deployed instances built with code at or before commit c07bd4c97141521af6475034bc58523beed51bbd are considered vulnerable because the project does not use versioning and the official fix has not been released. Therefore, any version of the application that has not yet incorporated the remediation is potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS score below 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw remotely by calling the vulnerable index endpoint, potentially bypassing authentication checks. The lack of explicit authentication prerequisites in the public description implies that the flaw could be exploited regardless of user credentials, making the risk moderate but unlikely to be widely observed today.
OpenCVE Enrichment