HIGH
An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbitrary locations on the server filesystem
Published Jun 9, 2026
8.8
HIGHCVSS 3.1
EPSS 1.43%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.