Impact
A flaw in the getBook endpoint of TaleLin's lin-cms-spring-boot allows an attacker to manipulate the ID parameter and gain unauthorized access to book records. This improper authorization can expose sensitive information stored in the system and is rooted in the weak permission verification logic, as indicated by CWE‑266 and CWE‑285.
Affected Systems
The vulnerability affects TaleLin lin-cms-spring-boot, specifically versions up to and including 0.2.1. Users running any of these releases are at risk and should verify they are on a fixed version beyond 0.2.1.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity with a non‑zero exploitation likelihood. The exploit is publicly available and can be carried out remotely by sending crafted HTTP requests to the vulnerable endpoint. EPSS information is not supplied, and the vulnerability is not listed in the CISA KEV catalog, but the presence of a remote attack vector and known public exploit make patching a priority.
OpenCVE Enrichment