Impact
The vulnerability is a path‑traversal flaw in the Download Preparation flow of ShareFile Storage Zones Controller that allows an authenticated zone administrator to specify a file path that lies outside the expected preparation directory. Because the controller does not properly sanitize the path, the attacker can write arbitrary files onto the system, potentially including executable payloads. On affected v5 releases, this leads to confirmed remote code execution, while on v6 the impact is not confirmed but the ability to overwrite system files remains.
Affected Systems
The flaw exists in Progress ShareFile Storage Zones Controller versions up through 5.12.5 and 6.0.2. Only the listed versions of the controller are compromised. Versions 5.12.6 and later, as well as 6.0.3 and later, have fixed the validation routine that mitigates the traversal error.
Risk and Exploitability
The CVSS base score of 7.2 indicates a high severity, reflecting the high potential impact for authenticated users. Attackers need portal access and zone‑administrator privileges, which limits the threat surface but still represents a significant risk within an organization that trusts such roles. The EPSS score is not public; nevertheless, the documented capability to write arbitrary files indicates that exploitation practices exist and could be replicated. As of now, the vulnerability is not listed in the CISA KEV catalog, but the possibility of remote code execution on v5 warrants immediate attention.
OpenCVE Enrichment