Impact
The flaw resides in the post_upload.php handler of theRealSain Pixtream, where the media parameter is accepted without validation. Because of this weakness, an attacker can supply a crafted payload that will be stored on the server as a file, effectively enabling an unrestricted file upload. This vulnerability could allow an attacker to place arbitrary content onto the web application, potentially leading to defacement, theft of information embedded in files, or other damage if the uploaded content is later executed by the server or users.
Affected Systems
Any deployment of theRealSain Pixtream up to commit 866afd4f0cea812b918780fb74b67dccf8c4d6a0 is potentially susceptible. The product does not employ versioning, so exact affected releases are not listed; however, every installation that exposes post_upload.php is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely; a public exploit has already been released, raising the likelihood that attackers may target affected installations before a vendor fix is issued.
OpenCVE Enrichment