Impact
A flaw in the JDBC Driver Upload component allows an attacker to upload any file to the server without restriction, violating proper authentication and authorization controls. This type of unrestricted upload can expose the system to arbitrary code execution or other malicious operations if executable files are uploaded and later executed.
Affected Systems
Software affected is CodePhiliaX Chat2DB, with vulnerable releases up to version 0.3.7. No subsequent releases are documented as safe in the provided data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploit potential is confirmed as public, and the vulnerability can be triggered over the network, i.e., remotely. Since EPSS data is unavailable and the issue is not in the KEV catalog, the overall threat is considered moderate but actionable due to the ease of remote exploitation.
OpenCVE Enrichment