Impact
The vulnerability causes Databasement to validate invitation tokens only once when the acceptance page is initially displayed, caching that decision for the duration of the session. Because the token is not rechecked during the actual acceptance step, an attacker who obtains a leaked or forwarded invitation link can load the page prior to the legitimate user, then complete the acceptance after the legitimate user has already accepted, thereby overwriting the account password and assuming full authenticated control over managed database credentials and secrets.
Affected Systems
The flaw exists in the David‑Crty Databasement application in all releases before version 1.7.14, including the 1.7.13 snapshot referenced in the advisory.
Risk and Exploitability
The CVSS score of 9.1 signals a critical level of risk. Although an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the attack vector appears to be remote, web‑based, and requires only a leaked or forwarded invitation URL. If an attacker can supply the stale token to a target account, they can replace the account’s password and gain privileged database access. The lack of immediate token revalidation and absence of contextual checks make the exploitation path straightforward once the invitation link is obtained.
OpenCVE Enrichment