Impact
The vulnerability allows an authenticated administrator to upload a file without proper extension validation, enabling the upload of a malicious ASPX file that can be executed by the web server. This leads to arbitrary code execution with the privileges of the web service account.
Affected Systems
All supported versions of BugTracker.NET from the vendor BugTracker.NET are affected. No specific version limits are mentioned in the data, implying that the defect exists in every release of the product.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. Although the EPSS score is not available, the lack of extension filtering and the ability to store uploads in a web‑accessible directory mean an attacker with administrator privileges could readily exploit the flaw. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet, but the potential for remote code execution remains significant.
OpenCVE Enrichment