Impact
A flaw allows an attacker to manipulate the data1 argument of the unlink function in the Faveo Helpdesk SettingsController, leading to path traversal that can delete arbitrary files on the server. The attacker can launch this attack remotely, and the disclosed exploit may be used publicly. The weakness is classified as CWE‑22 and results in direct loss of files or data, potentially disrupting business operations or compromising system integrity.
Affected Systems
All installations of Faveo Helpdesk up to version 2.0.3 are affected. The vulnerability resides in the Logo Handler component of the application. No other versions or components are known to be affected.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the flaw is publicly disclosed and can be triggered remotely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring the attacker to send crafted input to the SettingsController endpoint to perform a deletion of any file path specified by the attacker.
OpenCVE Enrichment