Impact
The vulnerability in metasfresh arises from the DocumentAttachmentsRestController and CommentsRestController endpoints, which verify only that a caller is logged in but fail to enforce record‑level permissions. Attackers can therefore enumerate sequential document identifiers and read, replace, or delete attachments and comments on records that their role should not be able to access, exposing confidential information and allowing unauthorized modification. This flaw is an access control bypass identified as CWE‑639.
Affected Systems
The impacted product is the metasfresh ERP platform, specifically the backend controllers that manage attachments and comments. While the CNA data does not specify affected versions, any installation of metasfresh that includes these controllers is potentially vulnerable. Administrators should confirm the product version in use and consult the vendor’s release notes for a fix.
Risk and Exploitability
With a CVSS score of 8.7 this flaw is categorized as high severity, and although the EPSS score is less than 1% indicating low current exploitation probability, the condition can be triggered by any authenticated user lacking proper record‑level rights. The attack vector is likely through authenticated API calls to the vulnerable endpoints; the issue is not yet flagged in the CISA KEV catalog but should be patched promptly given its high impact.
OpenCVE Enrichment