Impact
A file upload flaw in RainyGao-Hithub DocSys v.2.02.80 permits a remote attacker to run arbitrary code on the server, providing full control over confidentiality, integrity, and availability of the affected system. The vulnerability arises because uploaded files are not validated or restricted, allowing malicious code to be stored and executed without restriction. As a result, an attacker could compromise the entire application and potentially the underlying host.
Affected Systems
The vulnerability affects the RainyGao-Hithub DocSys product, specifically version 2.02.80. No other vendors or versions are documented as affected.
Risk and Exploitability
The flaw offers a high‑severity remote code execution path, with a CVSS score of 9.8. The EPSS score is less than 1%, indicating a low but non‑zero likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Exploitation is possible through the web interface that accepts file uploads, likely via a direct HTTP request to the upload endpoint, and does not require special privileges beyond access to that page.
OpenCVE Enrichment