Impact
An improper authorization flaw exists in the searchBook endpoint of TaleLin lin-cms-spring-boot, allowing attackers to bypass access controls and retrieve book information without proper credentials. The weakness is rooted in missing or incorrect authorization checks (CWE-266 and CWE-285) and can lead to unauthorized disclosure of potentially sensitive data. The CVSS score of 6.9 indicates moderate severity, reflecting the potential impact on confidentiality.
Affected Systems
The vulnerability affects all versions of the TaleLin lin-cms-spring-boot application up to and including 0.2.1. No newer versions containing a fix were listed in the data provided. Systems running the affected package without the patch are at risk.
Risk and Exploitability
The flaw can be exploited remotely, as indicated by the vendor description. While the EPSS score is not available, the public availability of the exploit suggests a real threat scenario. The vulnerability is not listed in CISA's KEV catalog, but the moderate CVSS score and remote exploit potential warrant timely remediation.
OpenCVE Enrichment