Impact
The vulnerability resides in the check_authentication function within changedetection.io's flask_app.py, allowing attackers to bypass normal authentication controls. By manipulating the authentication request, an attacker can gain unauthorized access to the application, potentially leading to data theft, unauthorized configuration changes, or other malicious activity. The flaw is classified as improper authentication (CWE‑287).
Affected Systems
Affected systems include instances of dgtlmoon changedetection.io up to and including version 0.60.7. No higher versions are known to be impacted, and a specific fixed version is not yet announced by the vendor.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, but the public disclosure of the exploit and the absence of a vendor response elevate the risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the issue remotely, making it feasible for a wide range of threat actors. Immediate remediation is recommended.
OpenCVE Enrichment