A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apprain
Apprain apprain |
|
| CPEs | cpe:2.3:a:apprain:apprain:4.0.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Apprain
Apprain apprain |
|
| Metrics |
cvssV3_1
|
Thu, 04 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Sep 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/. | |
| Title | Path Traversal vulnerability in appRain CMF | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-09-04T11:07:48.351Z
Updated: 2025-09-04T14:16:10.456Z
Reserved: 2025-04-16T09:09:29.024Z
Link: CVE-2025-41035
Updated: 2025-09-04T14:16:07.899Z
Status : Analyzed
Published: 2025-09-04T11:15:33.747
Modified: 2025-09-04T18:44:52.747
Link: CVE-2025-41035
No data.
ReportizFlow