Impact
The vulnerability allows an authenticated administrator to bypass content validation during an administrative file upload, enabling storage of files with dangerous content on the Kiteworks appliance. Although this does not by itself trigger code execution, placing malicious files increases the risk of future exploitation when combined with other weaknesses. The affected weakness is an unrestricted upload flaw (CWE‑434), which permits unauthorized file types to be stored.
Affected Systems
The affected product is Kiteworks Core. No specific version constraints are disclosed in the advisory.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires an administrator account and bypasses upload restrictions, but the stored file alone will not execute. An attacker could later weaponize the file through another vulnerability or malicious activity.
OpenCVE Enrichment