Impact
An unauthenticated file upload flaw in ck_upload_handler.php of Feng Office 3.11.13.11 lets attackers place malicious files such as .html into the publicly accessible /tmp/ directory. If the web server serves or interprets these files, the attacker can execute arbitrary code or inject malicious content, compromising the confidentiality and integrity of the system. The weakness stems from lack of input validation and improper restriction of file types (CWE‑434).
Affected Systems
All installations of Feng Office version 3.11.13.11 are affected. No other versions or vendors are reported as impacted in the available data.
Risk and Exploitability
The flaw carries a CVSS score of 9.8 and an EPSS score of less than 1 %, indicating a very low probability of exploitation at present, yet the impact remains severe. The vulnerability is accessible over the network, so remote attackers can exploit it without authentication. It is not listed in the CISA KEV catalog, but the high severity warrants immediate attention.
OpenCVE Enrichment