Impact
The flaw exists in the unlink operation of GEOFlow’s Image Library Cleanup component. By manipulating the file_path parameter, a remote attacker can traverse the file system and delete any file accessible to the web server. The vulnerability is a classic path traversal (CWE‑22) that results in file deletion, compromising data integrity and potentially disrupting application availability.
Affected Systems
yaojingang GEOFlow releases up to version 2.1.0 are affected. The security patch is included in GEOFlow 2.1.1, committed as 67abfd864a15d169a78429f3290c91cb3b93e849.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity. An EPSS score is not available and the issue is not listed in the CISA KEV catalog, yet the exploit is publicly disclosed and can be executed remotely. Because the attacker can delete arbitrary files, the risk of data loss and service disruption is tangible if the flaw is left unpatched.
OpenCVE Enrichment