Executive brief
The Priority Portal Generator addon to Priority ERP (an enterprise resource planning system) contains an observable discrepancy vulnerability that could allow attackers to gather sensitive information through response analysis. This weakness affects all versions lacking Priwall v3 protection, potentially exposing business process data or system behavior patterns that could be leveraged in further attacks.
Technical details
The vulnerability is classified as an observable discrepancy (information disclosure through timing or response analysis). The Portal Generator addon to Priority ERP fails to properly mask differences in system responses, allowing an attacker to infer sensitive information about application state or data through careful observation of responses. The issue affects all versions without Priwall v3 protection. The attack is network-accessible and does not require authentication. The practical impact is information disclosure that could enable reconnaissance for follow-up attacks or expose business-sensitive patterns. A patch via Priwall v3 is available.
Affected products
- Soft Solutions Portal Generator addon to Priority ERP all versions without Priwall v3
Timeline
- 2026-08-13: disclosed