Impact
The vulnerability is an unauthenticated remote file upload flaw that allows attackers to craft a POST request to /app-api/infra/file/upload and pass a directory parameter. The server does not properly validate or constrain the path, enabling the attacker to write files outside the intended storage directory. This arbitrary file placement can be used to upload malicious binaries or server-side scripts that an attacker can later execute, leading to full compromise of confidentiality, integrity, and availability on the affected host.
Affected Systems
The flaw is present in the LZ‑litchi application version 1.0.0. No other vendors or product versions are listed as affected in the available data.
Risk and Exploitability
Because the exploit requires no authentication and can be performed by any remote entity, the attack vector is clearly remote. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the nature of the flaw and the lack of authentication suggest a high likelihood of exploitation, especially for exposed installations. Absent an official patch, the risk remains high until a vendor update or a mitigated configuration is applied.
OpenCVE Enrichment