Impact
The flaw allows an authenticated administrator to supply malicious backup data that is decrypted and used to overwrite the application configuration file. By restoring a crafted configuration, the attacker can inject arbitrary command strings into protected fields such as TestConfigCmd. Subsequent invocation of the test endpoint executes those commands in the Nginx UI runtime context, giving the attacker full control over the server. This leads to compromise of confidentiality, integrity, and availability (CWE‑94).
Affected Systems
The vulnerability affects the 0xJacky nginx‑ui product in versions 2.3.8 through 2.4.x. All installations running any release from 2.3.8 up to, but not including, 2.5.0 are impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity. EPSS is not available, but the attack requires an authenticated administrator session and the ability to send HTTP requests. Since the vulnerability is tied to a specific API endpoint and relies on the application trusting supplied backup data, an attacker would need valid credentials or access to elevated privileges. The issue is not listed in the CISA KEV catalog, suggesting no known exploitation yet. Nonetheless, the combination of remote code execution and ease of exploitation makes the risk high.
OpenCVE Enrichment