Impact
MicroRealEstate’s file upload component is vulnerable to a relative path traversal flaw (CWE‑23). By supplying a filename that contains directory traversal sequences, an attacker could write data to arbitrary locations on the server’s filesystem, potentially overwriting system files and compromising application integrity.
Affected Systems
The flaw applies to all releases of MicroRealEstate up to and including version 1.0.0-alpha3. No other products are listed as affected.
Risk and Exploitability
The CVSS score is 7.1, indicating a high impact. The EPSS score is less than 1%, implying a low probability of exploitation at The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Based on the description, it is inferred that the attack vector is the publicly exposed file upload endpoint, which could be accessed over HTTP or HTTPS. If the server lacks directory confinement or filename filtering, an attacker can deliver a crafted filename to traverse directories and overwrite protected files.
OpenCVE Enrichment