Impact
The flaw in Intelliants Subrion CMS up to version 4.2.1 allows a remote attacker to manipulate the query parameter q in the /actions.json?action=assign-owner API call, which results in the disclosure of sensitive information. The vulnerability is systematically categorized as an information exposure and an improper authorization flaw, as the system fails to verify proper privileges before revealing data. This flaw directly compromises confidentiality by revealing data that should be protected from unauthenticated or unauthorized users.
Affected Systems
Intelliants Subrion CMS, all releases through version 4.2.1, including the /actions.json endpoint with the assign-owner action. Any deployment of the CMS that incorporates this endpoint is susceptible.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity risk, and while EPSS is not available, the vulnerability is listed as not in the KEV catalog. The exploit is openly available, and the description states that the attack can be executed remotely, suggesting that a web‑based request to the assign-owner API is sufficient to trigger the data leak. Given the public availability of the exploit code, an attacker with network access to the CMS can readily exploit the flaw without advanced prerequisites.
OpenCVE Enrichment