Impact
Kiteworks Core before version 9.5.0 allows an authenticated administrator to write a file to an arbitrary location on the underlying host through an administrative export feature that does not properly restrict the supplied file path. This flaw can lead to command execution on the appliance if an attacker can supply a payload that the host interprets as executable code. The vulnerability is an instance of path traversal (CWE‑22).
Affected Systems
The vulnerability affects Kiteworks Core, with all releases prior to 9.5.0 being susceptible. Systems running these versions without updated patches are at risk.
Risk and Exploitability
The CVSS v3 score of 7.2 indicates a high severity. EPSS data is not available, and the vulnerability is currently not listed in CISA’s KEV catalog. Exfiltration requires an authenticated administrative account with access to the export function, making the threat primarily internal or from compromised credentials. If exploited, the attacker can gain file write rights that may lead to remote code execution on the appliance.
OpenCVE Enrichment