Impact
The vulnerability is located in the User Attribute Update Endpoint of SveltyCMS 0.0.6, specifically within src/routes/api/[...path]/+server.ts. It allows an attacker to manipulate the endpoint without proper access checks, leading to unauthorized changes to user attributes. This flaw can enable privilege escalation or compromise of user accounts, as an attacker can set roles or permissions that should be restricted. The weakness is classified as improper authorization (CWE-284) and lack of privilege control (CWE-266).
Affected Systems
SveltyCMS version 0.0.6 is affected. Any installation using this version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the attack vector is remote, meaning an adversary can exploit the flaw from outside the network. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability has not been reported in the CISA KEV catalog, suggesting it may not have been widely exploited yet; however, the lack of access controls still presents a real risk for organizations that rely on the User Attribute Update Endpoint without additional safeguards.
OpenCVE Enrichment