CyberRota Analysis
AI-GeneratedThe Datiphy Data Management Center's upload API, versions 8.3.0 to 8.5.1, is vulnerable to external control of file names or paths, enabling remote attackers to write files to arbitrary locations outside the designated upload directory. This critical vulnerability could lead to unauthorized file access or system compromise. Organizations using affected versions should prioritize immediate remediation to mitigate potential exploitation risks.
Original NVD Description
External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.