Impact
admin3 versions up to 3.0.0 allow authenticated users to upload files whose names are not sanitized. By including a path with dot‑dot segments, an attacker can place the file outside the configured storage directory on Windows systems. The resulting write can overwrite any file that the server process can access.
Affected Systems
The vulnerability exists in the admin3 project hosted by cjbi, affecting all releases through 3.0.0. It is relevant on Windows deployments where the server writes files to the local filesystem.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. Because exploitation requires authentication and only occurs on Windows, the practical attack surface is limited to users with upload capabilities. No evidence of available exploits is present; the EPSS score is not available and the issue is not listed in the CISA KEV catalog. Nevertheless, an attacker could overwrite configuration, webroot, or other critical files, potentially enabling remote code execution or data tampering.
OpenCVE Enrichment