Impact
EFence contains an arbitrary file upload vulnerability that allows unauthenticated remote attackers to upload and execute a web shell backdoor. The flaw enables the attacker to run arbitrary code on the server, effectively compromising the entire system.
Affected Systems
The product vendor is Thinking Software Technology, and the affected implementation is EFence. All releases prior to version 1.2.67 (database version 57) contain the flaw and are vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and the vulnerability is not listed in CISA’s KEV catalog. While a current EPSS value is unavailable, the unprotected upload mechanism and lack of authentication make exploitation straightforward. Attackers can simply send a crafted HTTP request to the upload endpoint, place malicious code, and then invoke the uploaded script to achieve full code execution.
OpenCVE Enrichment