Impact
ContiNew Admin fails to enforce permission checks or file‑type validation on its multipart upload endpoints. Authenticated users can initiate a chunked upload, submit arbitrary file parts, and complete the upload, causing files with any extension to be stored in the backend storage. These files become reachable through web server URLs, creating opportunities for malicious content to be served to end users.
Affected Systems
The vulnerability affects ContiNew Admin version 4.1.0 and earlier, running on any platform supported by the continew-admin product. The affected component is the MultipartUploadController in the system module. Users of the 4.1.0 release must verify their installation and plan an update.
Risk and Exploitability
The CVSS score of 7.1 puts this issue in the high‑severity range. Because only authenticated users can exploit the flaw, the attack surface is limited to those with legitimate accounts, but the impact is severe once a malformed file is served. The EPSS score is not available, but the lack of a KEV listing indicates no widely demonstrated exploitation yet. Nonetheless, the possibility of arbitrary file placement is a compelling reason to treat this as a priority vulnerability.
OpenCVE Enrichment