Showing 1 vulnerability on this page for bonita_bpm_portal

Signals CISA KEV Ransomware Nuclei
bonitasoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

bonitasoft bonita_bpm_portal Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

CWE-22Jun 18, 20151 related artifact
CVSS5.0v2.0EPSS17.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX