Impact
A flaw in the /Report/Upload/UploadFormImg.ashx handler of Beijing Meite Software Technology’s U+Smart Enjoyment WebSite permits an attacker to manipulate the File argument and upload files without any restrictions. This vulnerability can be exploited remotely, enabling the delivery of arbitrary files, including executable code, which may lead to further compromise of the host system. The weakness maps to access‑control and unrestricted upload defects identified by CWE-284 and CWE-434, respectively.
Affected Systems
Beijing Meite Software Technology U+Smart Enjoyment WebSite version 18.6001.1096.1000 is known to contain the flaw; no other affected versions are listed in the current data.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity level. EPSS data is unavailable, and the vulnerability does not appear in the CISA KEV catalog. Because the attack can be launched from a remote source via the publicly exposed upload endpoint, the likelihood of exploitation depends on the site’s exposure and any existing countermeasures. The risk remains moderate until a vendor update is applied or mitigation controls are implemented.
OpenCVE Enrichment