Impact
An authenticated user can upload a malicious file through the /api/create-car-image endpoint, allowing the execution of arbitrary code on the host. The flaw results from insufficient validation of uploaded files, enabling attackers to place executable payloads that the application will run. This leads to full compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
Bookcars version 8.3 is affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The vulnerability requires authentication but is otherwise straightforward to exploit once access is obtained. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because it permits remote code execution, the risk is high. Attackers can use this flaw to gain persistent footholds, exfiltrate data, or pivot to other network assets.
OpenCVE Enrichment