CVE-2021-47978: ProcessMaker 3.5.4 Local File Inclusion via Path Traversal
ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47978?
CVE-2021-47978 is considered a critical vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2021-47978?
To remediate CVE-2021-47978, it's recommended to upgrade ProcessMaker to the latest version that addresses this local file inclusion vulnerability.
What type of vulnerability is CVE-2021-47978?
CVE-2021-47978 is classified as a local file inclusion vulnerability that exploits improper path traversal validation.
Who is affected by CVE-2021-47978?
CVE-2021-47978 affects users of ProcessMaker version 3.5.4 and potentially allows unauthenticated attackers to read arbitrary files.
What impact does CVE-2021-47978 have?
CVE-2021-47978 can lead to unauthorized access to sensitive information by allowing attackers to exploit file inclusion vulnerabilities.