Impact
An authenticated remote attacker can exploit a flaw in EasyAdmin v2.0.2.2 that permits unrestricted upload of files with dangerous types. This weakness is defined as CWE-434: Unrestricted Upload of File with Dangerous Type, which allows an attacker to execute arbitrary code on the server with elevated privileges. By uploading a crafted file through the background management interface, the attacker gains execution of arbitrary code, compromising confidentiality, integrity and availability of the system.
Affected Systems
The vulnerability affects only the EasyAdmin package version 2.0.2.2. No specific vendor names are provided, but administrators running EasyAdmin with the background management interface should verify the installed version.
Risk and Exploitability
The flaw is classified as a Remote Code Execution vulnerability with a CVSS score of 9.8, indicating critical severity. The EPSS score is < 1%, suggesting a very low but non-zero exploitation probability. The attack requires valid authenticated credentials to the background management interface, indicating it is not an unauthenticated remote attack. The lack of a KEV listing further implies limited exploitation activity to date. Nevertheless, given the high impact of arbitrary code execution, the risk remains elevated until the vulnerability is remediated.
OpenCVE Enrichment