Impact
File upload vulnerability in T-Systems International GmbH ImageMaster Version 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the add attachments feature in the create new document function. The flaw enables execution of code with the privileges of the application, potentially giving full control over the system. The weakness is a classic example of untrusted file processing, which can compromise confidentiality, integrity, and availability of the affected environment.
Affected Systems
The affected product is T-Systems International GmbH ImageMaster, specifically version 9.14.2.8.1. No other versions or vendors are listed.
Risk and Exploitability
The CVSS base score is 8.8, indicating a high risk. The EPSS score of 0.00587 (less than 1%) indicates a low overall exploitation probability, yet the high CVSS score and the remote nature of the attack mean that exploitation remains a serious threat. The vulnerability is not listed in CISA KEV. The attack vector is presumed to be a web‑based file upload via the application’s interface, given that the vulnerability is triggered by the add attachments feature. If an attacker can reach this file upload endpoint, they can deliver a malicious payload and launch arbitrary code execution.
OpenCVE Enrichment