Impact
OneNav v1.2.4 contains a flaw where an authenticated administrator can trigger deletion of arbitrary files in the application’s working directory by uploading a non‑HTML file whose name matches an existing file. The upload handler passes the attacker‑controlled filename directly to the unlink() function when rejecting the upload, resulting in the targeted file being deleted. This loss can lead to denial of service by removing critical configuration or data files and may erase sensitive information stored within the application directory. The weakness involves improper authorization (CWE‑706).
Affected Systems
The affected product is the OneNav web application, version 1.2.4. No other vendor information or package names beyond the GitHub repository are provided. The vulnerability is present in the Api::upload() method in Api.php.
Risk and Exploitability
The flaw requires authenticated administrator privileges; no external conditions are mentioned. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. However, within installations where administrative accounts are exposed or weakly protected, an attacker could delete configuration or data files, leading to downtime and potential loss of critical information. The attack path is straightforward: authenticate, submit a POST to the upload API with a non‑HTML file whose name matches an existing file; the server deletes that file when rejecting the upload. The weakness does not allow arbitrary code execution.
OpenCVE Enrichment