Impact
The vulnerability resides in the Upload function of Module.php within Bdtask’s Multi-Store Inventory Management System. By manipulating the module argument, an attacker can upload arbitrary files without restriction. The description does not detail the exact consequences, but based on the description, it is inferred that an attacker could place malicious scripts or web shells, facilitating further compromise of the application or underlying server. The impact is primarily the potential for executing code supplied by the attacker, leading to data tampering, confidentiality breaches, and possibly full system takeover.
Affected Systems
Bdtask’s Multi-Store Inventory Management System, version 1.0. No other versions or variants were listed as affected in the current data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS information is unavailable and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw can be exploited remotely via the upload endpoint, and a public exploit has already been released. No additional prerequisites beyond access to the upload URL are mentioned, suggesting a straightforward attack path for anyone who can reach the web interface.
OpenCVE Enrichment