Impact
The Smart Park Management System v2.0 contains an unrestricted file upload flaw in its upload module that permits attackers to upload arbitrary files and execute code on the server. This flaw, classified as CWE‑434, enables remote code execution with potential full compromise of the system. The vulnerability could allow attackers to gain unrestricted access to the host, modify or delete data, and disrupt operations.
Affected Systems
The affected product is the Smart Park Management System version 2.0. No vendor information is provided in the CNA data, and the references point to open‑source proof‑of‑concept code rather than an official vendor release.
Risk and Exploitability
The likely attack vector is the web application's file upload interface, requiring only network connectivity to send a crafted file. With a CVSS score of 9.8, the severity is high; the EPSS of <1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers could gain full control of the application server by uploading a malicious script and executing it in the context of the application.
OpenCVE Enrichment