Impact
This vulnerability allows an unauthenticated attacker to delete any file on the server by exploiting directory traversal sequences in the /api/delete-temp-license/{file} endpoint, enabling arbitrary file deletion and disrupting service integrity and availability.
Affected Systems
The affected software is bookcars version 8.3; vendor information is not specified, and no other versions are confirmed to be vulnerable based on the current data.
Risk and Exploitability
Because the endpoint is accessible without authentication, an attacker can remotely trigger deletions, posing a high risk to system availability and data integrity; the EPSS score of <1% indicates a low probability of exploitation, while the CVSS score of 5.3 suggests moderate severity, and the vulnerability is not listed in CISA KEV.
OpenCVE Enrichment