Impact
The vulnerability in İzometri IT Services eimzamip allows an attacker to upload files of dangerous types without restriction. This flaw can enable the execution of arbitrary code on the web server or the application, compromising confidentiality, integrity, and availability of the affected system. The weakness is a classic unchecked file upload flaw, classified under CWE-434.
Affected Systems
İzometri IT Services Domestic and Foreign Trade Co. Ltd. provides the eimzamip product. Versions affected are those from v1.6.4 up to but not including v1.6.6, i.e., any release prior to and including v1.6.5.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. The EPSS score is not available, so current exploitation likelihood cannot be quantified, but the issue is not listed in CISA KEV, implying no confirmed exploit yet. The likely attack vector is remote, via the web application’s file upload endpoint; an attacker with access to that interface can upload a malicious file and trigger code execution. The flaw requires that the victim’s environment accepts the file and that the uploaded payload has an execution context, such as a web application with sufficient privileges.
OpenCVE Enrichment