Impact
The vulnerability lies in the storage endpoint /storage/upload of cjbi admin3 v3.0.0, where no permission checks are performed. This allows any authenticated user to upload arbitrary files and any unauthenticated user to download them, enabling the exfiltration of data, delivery of malicious payloads, and unauthorized access to stored content, thereby compromising confidentiality and integrity.
Affected Systems
The affected product is cjbi admin3, version 3.0.0. No additional vendor details are available. The flaw affects the storage component exposed at the /storage/upload endpoint.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and the EPSS score of less than 1% suggests a low current likelihood of exploitation, though the risk remains significant due to the lack of authorization. The flaw can be exploited remotely via a web browser or automated scripts by any logged‑in user for uploads and by anonymous users for downloads, with no special prerequisites other than access to the instance. It is not listed in CISA KEV, but that does not negate its potential impact.
OpenCVE Enrichment