Impact
WEBCON BPS is vulnerable to an Insecure Direct Object Reference in the /api/vacations/{path} endpoint. The selectedPeople parameter used by the Gantt vacation chart API does not enforce authorization checks, allowing an authenticated user to submit arbitrary user identifiers. This flaw, classified as CWE-639, enables the attacker to read vacation schedules of any employee, including managers and staff from other offices, resulting in privacy violations and potential insider threat escalation.
Affected Systems
Affected products are WEBCON BPS from the vendor WEBCON. Versions prior to 2025.2.1.177 and 2026.1.1.20 contain the flaw. No further sub‑versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, reflecting that the vulnerability requires authentication and does not lead to code execution or service disruption. EPSS data is not available, but the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the web API, requiring an authenticated session. An attacker can exploit this by crafting requests to the impacted endpoint and supplying arbitrary user logins in the selectedPeople parameter. No zero‑day or known exploitation evidence is reported, but the straightforward nature of the flaw makes the risk of abuse significant for organizations using unmanaged or insecure API access.
OpenCVE Enrichment