Impact
OpenDocMan 2.4.0 through 2.10.0 includes a decompression bomb flaw that lets an authenticated user upload a small office file whose contents decompress to a large size, consuming PHP memory and causing worker processes to crash. This results in a denial of service on the application, potentially affecting all users. The weakness is a form of improper restriction of content from a remote source (CWE-409).
Affected Systems
The vulnerability affects OpenDocMan releases 2.4.0 to 2.10.0. Any environment running those versions is susceptible. Databases or file storage pools that host the application must consider that these releases process office documents (ODT, DOCX, and XLSX).
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the exploitability score is not available, but the flaw does not require additional privileges beyond valid upload rights. Since the issue is not listed in KEV and no EPSS data is present, current public exploitation risk is uncertain. However, an attacker with authenticated access can intentionally deplete memory, crash workers, and degrade availability, making this a critical impact for highly available services.
OpenCVE Enrichment