Impact
A path traversal flaw exists in the resumable upload initiation endpoint of Progress ShareFile Storage Zones Controller. The filename supplied by the uploader is not sanitized, letting an authenticated user with zone credentials craft a path that navigates outside the intended upload directory. This flaw enables writing arbitrary content to any filesystem location writable by the application’s service account and may allow execution of attacker supplied code.
Affected Systems
The vulnerability affects Progress ShareFile Storage Zones Controller version 5.12.5 and earlier. Versions 5.12.6 and later contain the fix.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Although EPSS data is not available, the flaw can be exploited by any user with valid zone credentials, locally on the server or via a web interface that exposes the upload endpoint. It is not listed in CISA’s KEV catalog, but the ability to write arbitrary files can lead to remote code execution, making this a serious threat pending patch.
OpenCVE Enrichment