Impact
The vulnerability allows an authenticated user to retrieve vulnerability findings from any organization by supplying arbitrary scan identifiers. The user receives complete web vulnerability data, including titles, severities, statuses, and analyst notes. This exposure violates confidentiality of vulnerability information from other tenants and can lead to strategic or security risks for those organizations. The flaw is an authorization bypass, as the system fails to verify that the requester owns the organization tied to the scan.
Affected Systems
ArcherySec, versions up to and including 2.0.6. The affected component is the WebScanVulnList endpoint of the application.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high severity. The EPSS score of less than 1% suggests a low likelihood of the vulnerability being actively exploited at this time. The vulnerability is not listed in the CISA KEV catalog, further indicating it is not a known high‑profile exploit. The attack requires authentication with normal user privileges and can be performed by sending requests to the WebScanVulnList endpoint with crafted scan IDs. Once accessed, an attacker can read data from other tenants without additional privileges.
OpenCVE Enrichment