Логотип exploitDog
bind:CVE-2025-41035
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-41035

Количество 2

Количество 2

nvd логотип

CVE-2025-41035

5 месяцев назад

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w4h7-75xh-3v83

5 месяцев назад

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-41035

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-w4h7-75xh-3v83

A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу