Impact
The Ocsreports component of OCS Inventory NG has an unrestricted file upload flaw in the CSV upload mechanism of the admin_info endpoint. The system only checks the supplied file name, ignoring actual file content or MIME type, which permits an administrator to upload arbitrary PHP files into a web-accessible directory. If the uploaded script is later processed, an attacker can execute code with the privileges of the web service account, compromising confidentiality, integrity, and availability of the server.
Affected Systems
All versions of Ocsreports bundled with OCS Inventory NG that predate the 2.12.6 release are susceptible. The vendor has released 2.12.6 and later revisions that address the issue. Organizations running earlier revisions should verify the exact version and apply the update.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.4, indicating a high severity impact. The EPSS score is not available, so the current exploitation probability cannot be quantified, and it is not listed in the CISA KEV catalog. Attacks require valid administrator credentials to reach the CSV upload endpoint; thus the likely attack vector is a privileged or authenticated intruder who can upload files, with potential consequences of arbitrary code execution on the host.
OpenCVE Enrichment