Impact
File upload vulnerability in T-Systems International GmbH ImageMaster Version 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function. The flaw enables execution of code with the privileges of the application, potentially giving full control over the system. The weakness is a classic example of untrusted file processing, which can compromise confidentiality, integrity, and availability of the affected environment.
Affected Systems
The affected product is T-Systems International GmbH ImageMaster, specifically version 9.14.2.8.1. No other versions or vendors are listed.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the nature of the flaw suggests a high likelihood of exploitation. The attack vector is presumed to be a web‑based file upload via the application’s interface, given that the vulnerability is triggered by the add attachments feature. If an attacker can reach the file upload endpoint, they can deliver a malicious payload and launch arbitrary code execution.
OpenCVE Enrichment