Impact
The vulnerability is an argument injection flaw in Fireshare’s video upload handler. When a crafted request is submitted, the application incorrectly processes input arguments, permitting the attacker to specify arbitrary file paths. This flaw allows an unauthenticated user to create or overwrite any file on the server, potentially injecting malicious code and gaining full host compromise. The weakness is classified as CWE‑88 and can result in remote code execution if critical system files are replaced.
Affected Systems
All installations of Fireshare prior to version 1.6.14, distributed by ShaneIsrael, are vulnerable. The flaw resides in the core upload functionality and is not limited to a specific configuration; any public or self‑hosted instance running a version older than the fix is affected.
Risk and Exploitability
The CVSS score of 9.8 marks the issue as critical, while the EPSS score of < 1 % indicates a presently low exploitation probability. The attack vector is a web‑based upload endpoint that requires no authentication. If exploited, an attacker could overwrite essential files and achieve remote code execution. The vulnerability is not listed in the CISA KEV catalogue, but the high severity warrants close attention.
OpenCVE Enrichment