Impact
The vulnerability resides in the FastDFSUtils.upload routine that handles the /hr/userface endpoint of the lenve vhr application. By manipulating the File argument, an attacker can upload arbitrary files to the server. Although the description does not confirm code execution, it is inferred that the ability to place malicious files on the filesystem could enable further attacks, such as hosting malware or attempting to execute payloads through additional vectors.
Affected Systems
This issue affects the lenve vhr product, specifically the Avatar Upload component in the 1.0-SNAPSHOT release. No other versions or products are mentioned as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. A public exploit is available, and the attack can be carried out remotely, making the risk significant. The flaw allows uploading of arbitrary files, which could be leveraged for subsequent attacks, though direct execution of uploaded content has not been confirmed. Based on the description, it is inferred that such files may be used for further exploitation.
OpenCVE Enrichment