What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Lenderd 1003 Mortgage Application allows Relative Path Traversal.This issue affects 1003 Mortgage Application: from n/a through 1.75.
Explanation of Vulnerability in Simple Terms
02Summary
The 1003 Mortgage Application contains a path traversal vulnerability that allows authenticated users to read arbitrary files from the server. An attacker with low-level access can bypass directory restrictions and access sensitive data outside the intended application folder. The vulnerability affects versions up to 1.75 and requires network access and valid credentials to exploit.
What an attacker can do
03Attacker Capabilities
Read arbitrary files from the server, including configuration files and other sensitive data.
Potential impact on your site
04Site Impact
Sensitive files (database configs, API keys, user data) may be exposed to authenticated users with low privileges.
Conditions required to exploit
05Prerequisites
Attacker must have a valid user account with low-level privileges and network access to the application.
Key dates
06Disclosure timeline
May 17, 2024
CVE published
April 28, 2026
Record updated