A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a user to query the "/api/sftp/users" endpoint. This could allow an authenticated remote attacker to gain knowledge about the list of configured users of the SFTP service and also modify that configuration.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
During installation, installed file permissions are set to allow anyone to modify those files.