A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Sep 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apprain
Apprain apprain |
|
CPEs | cpe:2.3:a:apprain:apprain:4.0.5:*:*:*:*:*:*:* | |
Vendors & Products |
Apprain
Apprain apprain |
|
Metrics |
cvssV3_1
|
Thu, 04 Sep 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 04 Sep 2025 11:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/. | |
Title | Path Traversal vulnerability in appRain CMF | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-09-04T11:07:48.351Z
Updated: 2025-09-04T14:16:10.456Z
Reserved: 2025-04-16T09:09:29.024Z
Link: CVE-2025-41035

Updated: 2025-09-04T14:16:07.899Z

Status : Analyzed
Published: 2025-09-04T11:15:33.747
Modified: 2025-09-04T18:44:52.747
Link: CVE-2025-41035

No data.