Impact
Based on the description, it is inferred that an authenticated low-privileged user can send specially crafted requests that trigger unauthorized data access and modification, potentially compromising data integrity and confidentiality. The vulnerability, classified as CWE-89, Detection System (ADS).
Affected Systems
Progress Software Flowmon ADS versions prior to 12.5.6 and 13.0.5 are affected.
Risk and Exploitability
Based on the description, it is inferred that the attack is internal to the ADS. The CVSS score of 8.7 reflects a high severity issue. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV and low-priv internal to the ADS. A determined attacker with a legitimate session can exploit the flaw by sending malicious requests, leading to unauthorized data access and modification. The lack of exploitation does not negate the risk, as the vulnerability can still be leveraged for impactful data tampering.
OpenCVE Enrichment