Impact
A flaw in the Image Handler of CoCoTeaNet CyreneAdmin allows an attacker to craft a special Avatar parameter to walk out of the designated file directory and read arbitrary files on the host. This path traversal weakness can expose sensitive configuration files, credentials, or other confidential data and therefore threatens confidentiality. The vulnerability corresponds to CWE‑22.
Affected Systems
The affected product is CoCoTeaNet CyreneAdmin, with all releases up to and including 1.3.0 vulnerable. The flaw resides in the /api/system/user/getAvatar endpoint and is present regardless of product component configuration. Any installation exposing this API is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, though a publicly disclosed exploit demonstrates the practical ability to read files. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring only an HTTP request to the vulnerable endpoint. The potential impact of accessing arbitrary files makes this issue a serious concern for publicly exposed instances.
OpenCVE Enrichment