Impact
The flaw exists in the uploadRemote function of Andreimarcu Linux Server and allows a remote attacker to retrieve sensitive data that is not meant for public exposure. This issue is classified as a remote information disclosure (CWE‑200) and carries a CVSS score of 9.1, indicating critical severity. An attacker can exploit it by sending a crafted request to the uploadRemote endpoint without needing elevated privileges, thereby gaining unauthorized access to protected information.
Affected Systems
Andreimarcu Linux Server versions 1.0 through 2.3.8 are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.1 highlights high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV, implying no widespread public exploit has been reported. Exploitation is possible over the network by any user who can communicate with the server, without authentication, and is most likely achieved via a remote request to the uploadRemote endpoint, inferred from the description of the affected function.
OpenCVE Enrichment