Impact
The vulnerability is an authorization bypass in the user message deletion endpoint. The controller accepts a list of message identifiers without validating the requester's ownership of those messages, allowing any authenticated user to remove messages belonging to other users or announcements. This removal also deletes receipt records for all recipients, effectively erasing message history and potentially disrupting communications.
Affected Systems
ContiNew Admin version 4.1.0 is affected. Administrators and standard users alike can exploit the capability to delete messages they do not own, affecting the entire messaging subsystem within the application.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high risk, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The lack of a KEV listing also reduces the immediate prestige risk. However, the vulnerability requires only valid user credentials, making it relatively easy for attackers with legitimate accounts to carry out unauthorized deletions. The impact can include loss of critical information, disruption of user communication, and potential compliance violations.
OpenCVE Enrichment