Impact
NetKids iMark, supplied by Integrated Systems Technologies, Inc., includes an Uncontrolled Search Path Element flaw (CWE‑427). An attacker who can authenticate to the application can leverage this weakness to execute arbitrary code with SYSTEM privileges. The primary impact is the ability to run code with full local system rights, compromising confidentiality, integrity, and availability of the affected host.
Affected Systems
The vulnerability affects Integrated Systems Technologies, Inc. NetKids iMark. No specific removed or fixed product versions are listed in the advisory; therefore all installations of NetKids iMark that have not been updated or patched are susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk profile. EPSS data is not available, so current exploit probability cannot be quantified, and the vulnerability is not registered in CISA KEV. The likely attack vector requires an authenticated session to the application; an attacker would need to obtain valid credentials or take advantage of an existing authenticated user to trigger the path‑tracing behavior that allows code execution.
OpenCVE Enrichment