Impact
An arbitrary file upload flaw allows unauthenticated remote attackers to construct a POST request to /app-api/infra/file/upload and supply a directory parameter that is not validated server‑side. The lack of path sanitization permits writing files outside the intended storage directory, so attackers can place malicious binaries or scripts on the host. If such a file is executable, the attacker can later run it, potentially gaining full control of the system, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability is present in the LZ‑litchi application version 1.0.0. No other vendors or product versions are listed as affected.
Risk and Exploitability
Because the exploit requires no authentication and can be performed by any remote actor, the attack vector is remote. The EPSS score is 0.00176 (~0.18%), and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 9.8 and the lack of authentication suggest a high likelihood of exploitation, especially for exposed installations. Absent an official patch, the risk remains high until a vendor update or a mitigated configuration is applied.
OpenCVE Enrichment