CyberRota Analysis
AI-GeneratedEch0 versions prior to 4.4.3 are vulnerable due to inadequate scope-based authorization on nine admin endpoints related to comment moderation. This flaw allows attackers with limited-scope access tokens to perform critical actions such as listing, approving, rejecting, and deleting comments, as well as modifying system settings. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized comment management and potential abuse.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.