Impact
This vulnerability arises from improper authentication controls and insufficient file type validation at an API endpoint. An unauthenticated remote attacker can upload arbitrary files to a web‑accessible directory, enabling execution of arbitrary code and full compromise of the system.
Affected Systems
The flaw affects the Manacle Technologies Multi‑tenant ERP System. No specific version information is available; the vulnerability applies to the system as a whole across all installations.
Risk and Exploitability
The CVSS score of 10 indicates critical severity, and the EPSS score is unavailable. The vulnerability is not listed in the official KEV catalog. An attacker can exploit it remotely without authentication by posting a malicious file through the affected API. The combination of high impact and ease of exploitation results in a very high risk posture for organizations still running the vulnerable ERP.
OpenCVE Enrichment