What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms arforms allows Path Traversal.This issue affects ARForms: from n/a through <= 6.4.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
What the vulnerability does
Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms arforms allows Path Traversal.This issue affects ARForms: from n/a through <= 6.4.1.
Explanation of Vulnerability in Simple Terms
ARForms versions 6.4.1 and earlier contain an information disclosure vulnerability. An attacker with low-level user privileges can read sensitive data from the application, potentially including confidential information stored in the system. The vulnerability requires network access and valid user credentials but no additional user interaction. Scope is changed, meaning the impact may extend beyond the vulnerable component itself.
What an attacker can do
Read sensitive data and confidential information from the application.
Potential impact on your site
Unauthorized users with basic accounts can access confidential data they should not see.
Conditions required to exploit
Valid user account with low-level privileges; network access to the application.
Key dates
External resources
Related vulnerabilities