Impact
The flaw lies in the ft2.php component of FileThingie version 2.5.7, allowing a remote attacker to retrieve sensitive information without authentication. This results in an information disclosure and is classified as CWE-200, with a CVSS score of 9.9 indicating a very high exploitation potential.
Affected Systems
The vulnerability affects only FileThingie v2.5.7. No other products or versions are listed as impacted.
Risk and Exploitability
The flaw can be exploited remotely by accessing the ft2.php endpoint, enabling an attacker with network access to read confidential data. The EPSS score indicates a very low probability of exploitation (< 1%), yet the high CVSS of 9.9 and lack of authentication demonstrate that the risk remains substantial. The vulnerability is not listed in the CISA KEV catalog, yet its severity warrants immediate attention. An attacker does not need local privileges or elevated permissions to exploit the vulnerability; sending a crafted request to the exposed endpoint is sufficient.
OpenCVE Enrichment