Executive brief
MicroRealEstate, an open-source property management platform, contains a security flaw in its file upload system. An attacker can exploit this to save files in unauthorized locations on the server, potentially overwriting critical system files. This could lead to severe service disruptions, data corruption, or a complete system crash.
Technical details
A relative path traversal vulnerability (CWE-23) exists in the file upload functionality of MicroRealEstate through version 1.0.0-alpha3. The application uses parameters passed directly in a URL to determine the destination file path when writing uploaded files to disk. A remote attacker with low privileges can manipulate these parameters to traverse directories and write files to unauthorized locations. This can result in the overwriting of critical system files, leading to a denial of service or platform corruption. As of the advisory date, no fixed version has been identified.
Affected products
- MicroRealEstate MicroRealEstate through 1.0.0-alpha3
Timeline
- 2026-07-07: advisory: Advisory published by The Missing Link Australia and NVD