Impact
An arbitrary file upload flaw exists in the uploadMarkdownPic endpoint of DocSys-master V2.02.85. The code does not perform validation on the type or content of the uploaded file, allowing an attacker to place any file on the server through the web interface. If the uploaded file is executable or contains malicious payloads, the attacker could achieve remote code execution or compromise the confidentiality and integrity of the system.
Affected Systems
The vulnerable component is the DocSys-master web application, version 2.02.85. No other vendors or product versions are listed in the advisory.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of enforcement on uploaded file types suggests a high likelihood of exploitation in environments where the uploadMarkdownPic endpoint is publicly accessible. The flaw can be triggered over the network by any external user interacting with the web interface, and no authentication or privilege requirements are indicated in the description.
OpenCVE Enrichment