Impact
The vulnerability in the User Profile API exposes an authorization bypass when an attacker manipulates the ID argument in the /user/ endpoint. This flaw allows a remote actor to access or modify other users’ profiles without following the intended access controls, potentially leading to data disclosure or unauthorized data manipulation. The weakness is a classic example of improper authorization and parameter manipulation, as identified by CWE-285 and CWE-639.
Affected Systems
The affected product is Omega Solution FBP Fulfillment by People, specifically the 2025 release. The vulnerability exists in the /user/ component of the User Profile API. No other versions or platforms are confirmed to be susceptible, but any installation running the 2025 release should be evaluated.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate overall impact. The exploit is known to be remote and has been publicly disclosed, meaning attackers can attempt the bypass over a network. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the public disclosure suggests that exploitation attempts may occur. The attack vector is therefore remote, relying on crafted API requests; no local privilege or physical access is required.
OpenCVE Enrichment