Impact
A Cross‑Site Request Forgery flaw (CWE‑352) exists in the uploadPutHandler function of the Andreimarcu Linux‑Server application. The vulnerability allows a remote attacker to forge a request that the server accepts as if it came from an authenticated user, thereby enabling arbitrary code execution within the server process. This breach can compromise the confidentiality, integrity, and availability of the host system.
Affected Systems
Andreimarcu Linux‑Server (GitHub project) versions 1.0 through 2.3.8 are vulnerable. Versions beyond 2.3.8 are unverified, so the impact of newer releases is unknown.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an attacker can trigger the vulnerable endpoint from an arbitrary origin, bypassing CSRF checks and executing arbitrary code without requiring user authentication. Given the minimal prerequisites, exposed instances face an elevated risk.
OpenCVE Enrichment