Impact
A file upload flaw in RainyGao-Hithub DocSys v.2.02.80 permits a remote attacker to run arbitrary code on the server, providing full control over confidentiality, integrity, and availability of the affected system. The vulnerability arises because uploaded files are not validated or restricted, allowing malicious code to be stored and executed without restriction. As a result, an attacker could compromise the entire application and potentially the underlying host.
Affected Systems
The vulnerability affects the RainyGao-Hithub DocSys product, specifically version 2.02.80. No other vendors or versions are documented as affected.
Risk and Exploitability
The flaw offers a high-severity remote code execution path. While the EPSS score is not available, the lack of a KEV listing and the nature of the bug suggest that the risk is significant and exploitation is possible through the web interface that accepts file uploads. The attack vector is likely a direct HTTP request to the upload endpoint, and no special privileges appear required beyond the ability to access that page.
OpenCVE Enrichment