Impact
The vulnerability exists in the rename function of Admin File Manager’s file-manager.php script. An attacker can exploit the logic to upload any file that the web server can handle, without limitations on format or location. The flaw can be triggered remotely via the web interface. Uploaded files could contain malicious code that, if executed by the web server, may compromise the system’s confidentiality, integrity, or availability.
Affected Systems
The issue is present in synaptikcms synaptik-cms version 1.3.4.4 and earlier. The leverage point is the Admin File Manager component, specifically file-manager.php. Version 1.3.5 and later contain the fix, making those releases immune to the flaw.
Risk and Exploitability
The CVSS base score of 5.1 classifies the flaw as medium severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit remotely through the web interface by sending crafted rename requests, and the ability to upload arbitrary files raises the risk of malicious code execution if the server serves the file. Overall, the threat remains moderate but should be mitigated promptly.
OpenCVE Enrichment