Impact
A path traversal flaw in the deleteFile method of FileServiceImpl.java allows an attacker to remove arbitrary files from the filesystem. When exploited, the attacker can cause loss of data and potentially disrupt services or delete sensitive configuration files, thereby impacting data integrity and availability.
Affected Systems
The vulnerability affects the production_ssm and ssm-erp applications developed by feng_ha_ha and megagao. Versions up to the commit 4288d53bd35757b27f2d070057aefb2c07bdd097 are impacted, thus any deployed instance of these products that has not yet been patched or upgraded is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests that the likelihood of exploitation is low; however, the vulnerability has been publicly disclosed and active exploits have been reported. Because the attack can be performed remotely without authentication, the risk to organizations that expose the deleteFile endpoint over the network is significant until a patch is applied.
OpenCVE Enrichment