Impact
The flaw in the upload API endpoint allows a remote attacker to specify relative or absolute file paths, enabling the creation or overwrite of files outside the intended upload directory. This uncontrolled file write can result in sensitive configuration files being corrupted or malicious executables being stored, which in turn can provide a foothold for remote code execution. The weakness is classified as CWE‑73, External Control of File Name or Path.
Affected Systems
Datiphy Inc. Data Management Center versions 8.3.0 through 8.5.1 are affected.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the attack vector is remote via the exposed upload API. If an attacker can reach this endpoint, they can manipulate file paths to write arbitrary files, making exploitation feasible under normal conditions.
OpenCVE Enrichment