Impact
PatrowlManager versions through 1.8.4 allow an attacker who has logged in with a low‑privilege account to call the users listing API and retrieve the full list of users, including their privilege flags such as superuser or staff status. This vulnerability is an improper access control flaw (CWE‑862) that exposes sensitive membership information and could enable attackers to gain insight into privileged accounts. The impact is primarily confidentiality and integrity of account information, not direct system compromise. The vulnerability is limited to authenticated users, yet because the authentication required is only that of a normal user, the barrier to exploitation is low.
Affected Systems
The flaw exists in PatrowlManager, version 1.8.4. Users running this or earlier releases are affected. The product is offered by Patrowl.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score of less than 1 % suggests that exploitation is currently rare or unlikely. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited remotely by any authenticated user; the attacker simply performs an HTTP request to the user listing endpoint. Because the decorator that should enforce higher‑privilege checks is commented out, the endpoint accepts any authenticated request. The attack does not require elevated privileges or auxiliary tools, making the attack path straightforward once credentials are obtained.
OpenCVE Enrichment