Impact
The AddProductCode.php script in Neethuharii Café Management accepts an image argument that is processed without validation, allowing an attacker to upload arbitrary files. This unrestricted upload can be used to place malicious scripts on the web server, which, if later executed, results in remote code execution. The flaw is exploitable from a remote location and public exploit code is available.
Affected Systems
The vulnerable component is the AddProductCode.php endpoint of the Neethuharii Café Management application. Because the product follows a rolling release model, no specific version numbers are provided; any deployment of Café Management that incorporates the unpatched code is potentially affected.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, the release of a public exploit demonstrates that attacks are feasible. The attack vector is remote via the web interface, and the exploit does not require advanced prerequisites beyond submitting a malicious file through the image field.
OpenCVE Enrichment