Impact
OneNav 1.2.4 includes an authentication‑bound flaw in the import_link() function that allows an attacker who has logged in to delete any file on the system. The deletion can target critical application or system files, leading to data loss or denial of service. The vulnerability is a direct result of insufficient input validation and privilege control, which permits the authenticated user to specify arbitrary file paths for removal.
Affected Systems
The affected product is OneNav version 1.2.4. No other versions or vendors are explicitly listed in the CVE data. The vulnerability applies only to installations of this specific release.
Risk and Exploitability
Exploitation requires that the attacker possess valid user credentials within the OneNav application; the attack vector is local/authenticated. Because the EPSS score is not available and the CVE is not listed in the CISA KEV catalog, the likelihood of widespread exploitation cannot be precisely quantified. Nevertheless, the impact of deleting arbitrary files can be severe if critical directories are targeted, and the flaw can be triggered with minimal effort by an authenticated user who has permissions to invoke import_link().
OpenCVE Enrichment