Impact
A flaw in the SysFileController.upload method of huanzi‑qch base‑admin allows an attacker to upload any file because the implementation does not validate the File argument. The CVE description states that manipulating this argument can result in unrestricted upload, potentially allowing malicious files to be stored on the server.
Affected Systems
All builds of huanzi‑qch base‑admin that include the SysFileController component are potentially vulnerable. The project uses continuous delivery with rolling releases and no version information is available, so any deployment containing this component, regardless of its apparent revision, may be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation at the present time. The vulnerability is not listed in CISA KEV. An attacker can trigger the flaw remotely using crafted HTTP requests to the upload endpoint, and the exploit code is publicly available.
OpenCVE Enrichment