Impact
An authenticated user can upload a malicious file to /api/create-car-image, and the application will execute this payload. The flaw stems from insufficient validation of uploaded files, allowing attackers to run arbitrary code on the host. This can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Bookcars version 8.3 is affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The vulnerability requires authentication, so the attack vector is inferred to be via an authorized user's use of the /api/create-car-image endpoint. The EPSS score is < 1%, indicating a low probability of exploitation, and it is not listed in the CISA KEV catalog. The CVSS score of 5.4 reflects moderate severity; however, because execution of code is possible, attackers could gain persistent footholds, exfiltrate data, or pivot to other network assets after authentication.
OpenCVE Enrichment