Impact
An arbitrary file upload flaw in AppNitro MachForm v30 allows attackers to upload a specially crafted .phar file that triggers code execution on the host server. The vulnerability gives the attacker full control over the application environment, potentially compromising the underlying operating system, databases, and any data the application handles. This type of flaw has a high confidentiality, integrity, and availability impact, as it may allow disclosure of sensitive data, modification of application logic, and possibility of further lateral movement within the network.
Affected Systems
AppNitro MachForm version 30 is affected. No other vendor or product is listed in the CNA data, but any deployment of this application version is susceptible to the flaw.
Risk and Exploitability
The vulnerability can be exploited via the web application's file upload interface, allowing a remote attacker to upload malicious content without authentication if the application does not enforce proper file type validation. While the explicit EPSS score is not available, the flaw provides remote code execution, a rare high-impact scenario that is often actively exploited when disclosed. The CVE does not appear in the CISA KEV catalog, but its RCE nature warrants immediate attention. Attacker prerequisites include network reach to the file upload endpoint and the ability to craft a valid PHAR file. Once uploaded, the VFS or unpacking logic will execute the embedded code, giving the attacker control.
OpenCVE Enrichment