Impact
This vulnerability allows an unauthenticated attacker to delete any file on the server by exploiting directory traversal sequences in the /api/delete-temp-license/{file} endpoint, enabling arbitrary file deletion and disrupting service integrity and availability.
Affected Systems
The affected software is bookcars version 8.3; vendor information is not specified, and no other versions are confirmed to be vulnerable based on the current data.
Risk and Exploitability
Because the endpoint is accessible without authentication, an attacker can remotely trigger deletions, posing a high risk to system availability and data integrity; the absence of EPSS and KEV data suggests a moderate to high potential, but formal severity metrics are not provided.
OpenCVE Enrichment