Impact
The vulnerability allows an authenticated administrator to import a file into Kiteworks Core without fully verifying its contents, because the system checks only the file header. This insufficient verification, identified as CWE‑345, means that forged or corrupted data can be accepted and processed, compromising the integrity of the information in the system.
Affected Systems
Kiteworks Core is the affected product; specific version information is not provided, so all deployments using this application should verify whether the import logic is present.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated administrative access and no evidence of public exploitation. The risk arises from the possibility of integrity tampering rather than confidentiality or availability loss.
OpenCVE Enrichment