Impact
The vulnerability allows authenticated non‑administrative users to upload a file with a crafted name that escapes the intended data directory. This path‑traversal flaw lets an attacker place or overwrite files outside the application’s managed storage, potentially introducing malicious code into areas of the filesystem that the web application can execute. The result is unauthorized file placement with the privileges of the application process, a classic gateway to remote code execution or data tampering.
Affected Systems
The flaw affects installations of LubeLogger version 1.6.7 or earlier. The vendor is Hargata and the affected product is the LubeLogger web application. The issue is fixed in release 1.6.8.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. No EPSS data is available and the vulnerability is not listed in CISA’s KEV catalog. The attack requires authenticated access to the upload endpoint and does not rely on special system privileges, so the exploitation complexity is low. Because the attacker can directly control the uploaded file name, the path traversal is straightforward once the user is authenticated, making the flaw a strong candidate for internal compromise or exploitation by a malicious user with read/write rights to the application.
OpenCVE Enrichment