What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.
Explanation of Vulnerability in Simple Terms
ARForms versions 6.4 and earlier contain a path traversal vulnerability that allows authenticated users to cause a denial of service by disrupting site availability. An attacker with low-level access can exploit this flaw through the network without user interaction. The vulnerability affects the entire application scope, making it a significant risk for multi-tenant or shared environments.
What an attacker can do
Disrupt site availability and cause denial of service through path traversal exploitation.
Potential impact on your site
Site availability can be disrupted by authenticated users with low privileges, affecting all users.
Conditions required to exploit
Attacker must have low-level authenticated access to the application.
Key dates
External resources
Related vulnerabilities