Impact
Aetopia Digital Asset Management 1.0.0 contains a server‑side template injection flaw in the Add/Update Project API that allows an attacker to supply malicious content in the name or description fields. The templating engine renders that input, resulting in arbitrary code execution on the host system. The weakness corresponds to CWE‑94 and can lead to full compromise of the asset repository, affecting confidentiality, integrity, and availability.
Affected Systems
The sole affected product is Aetopia Digital Asset Management version 1.0.0. No other vendors or product versions are listed. Patch status is not publicly documented.
Risk and Exploitability
The vulnerability permits code execution on the server, but the EPSS score of less than 1% indicates a very low probability of exploitation, and it is not listed in CISA KEV. Attackers would need remote access to the Add/Update Project endpoint. The CVE description does not specify authentication requirements, so that is currently unknown. Without a public exploit, the immediate threat is limited, but the impact remains severe if encountered.
OpenCVE Enrichment