Impact
The setAvatar function accepts a File argument that can be manipulated to upload any file type without validation of content or type. The vendor does not perform checks on the file being uploaded. The uploaded files are saved in a directory that is directly accessible from the web. Because of this, a malicious user could upload a non‑image file, for example a PHP script, into that directory. It is inferred that if the web server is configured to execute scripts in that directory, the uploaded script could be run, which would provide remote code execution, although the official description does not explicitly state that this outcome is guaranteed.
Affected Systems
All installations of WuzhiCMS up to and including version 4.1.0 are affected. The flaw resides in the member::setAvatar method of the avatar upload component accessed via /index.php?m=member&f=user&v=setAvatar.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity level. The EPSS score is below 1%, suggesting that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and does not require authentication; an attacker can reach the upload endpoint from any network‑connected device and submit a crafted file. Because the upload allows arbitrary files to be stored in a web‑accessible directory, it is inferred that execution of a malicious script may be possible depending on server configuration, potentially leading to remote code execution. However this is an inference based on the upload path, not a confirmed feature in the description.
OpenCVE Enrichment