Impact
The vulnerability in the deleteBackup method of the BackupController allows remote actors to trigger a denial‑of‑service condition by manipulating the request flow. The flaw is classified as CWE‑404, indicating missing or inadequate error handling that permits the system to become unavailable. The affected code resides in the file handler component of qinming99 dst‑admin.
Affected Systems
All installations of qinming99 dst‑admin up to and including version 1.5.0 are affected. The faulty logic resides in the deleteBackup endpoint of the File Handler controller, which can be invoked remotely by an attacker with the ability to submit crafted requests.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity range, while the EPSS value of less than 1 % suggests that exploitation is presently unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog, but an exploit is publicly available, and the attack can be initiated remotely from outside the host. Given the medium severity and the possibility of a remote denial‑of‑service, systems running the affected version should treat this as a moderate risk that requires timely remediation.
OpenCVE Enrichment