Impact
The flaw in MyComplianceOffice MCO allows attackers to craft a filename that bypasses the application’s directory resolution logic, writing files to arbitrary locations on the server. In addition, the error messages returned when the filename is rejected expose absolute server paths, satisfying an information‑exposure weakness. Together the mechanics satisfy CWE‑22 and CWE‑209 and enable non‑privileged file creation or modification as well as leakage of sensitive path information.
Affected Systems
The vulnerability has been confirmed in version 25.3.3.1 of MCO. Based on the lack of an official fix or vendor response, it is inferred that other releases may also contain the same issue.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as moderate. The EPSS score of less than 1 % means current exploitation activity is very low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack is likely to be carried out by manipulating the file export or upload endpoints that accept a filename parameter, allowing a malicious user to induce the application to write a file anywhere on the server or disclose paths through generated error messages.
OpenCVE Enrichment