Impact
The vulnerability in EFence permits authenticated remote attackers to upload arbitrary files and execute web shell backdoors, leading to full code execution on the target server. This flaw is a classic Arbitrary File Upload weakness, allowing attackers to bypass intended security controls by placing malicious scripts into the web application’s storage area. Attacks would compromise confidentiality, integrity, and availability of the affected system, potentially giving attackers persistent footholds.
Affected Systems
Thinking Software Technology’s EFence product is affected. The vulnerability exists in installations that have not applied the recommended update to version 1.2.67 (database version 57) or newer. No additional affected vendor versions are listed in the provided data.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. No EPSS score is available, so the current data does not reflect the likelihood of exploitation, but the lack of a KEV listing suggests no widespread exploitation has been reported yet. The flaw requires authentication, so the attack surface is limited to users who already have legitimate access, but once an attacker obtains such credentials, they can upload malicious code without further constraints. The current documentation does not detail additional preconditions beyond authentication.
OpenCVE Enrichment