Impact
The vulnerability allows an attacker to upload a file of a dangerous type, such as a web shell, to the server. Once uploaded, the shell can be executed, giving the attacker the ability to run arbitrary commands on the host. This flaw represents an unauthorized code execution scenario and is classified as CWE-434.
Affected Systems
The issue affects the Bimser Solution Software Trade Inc. eBA Plus Document and Workflow Management System. Vulnerable implementations are present in releases from version 6.7.141 up to and including 10.0.10. Versions 10.0.11 and later are not affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed exploitation reports yet. The attack vector is inferred to be via the web upload interface, requiring access to the upload functionality; after upload, execution is possible if the web server interprets the file as executable.
OpenCVE Enrichment