nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47978 CVE-2021-47978
MEDIUM
ProcessMaker 3.5.4 Local File Inclusion via Path Traversal
Record summary
CVE-2021-47978 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without authentication.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ProcessMakerBrowse Processmaker / ProcessMaker | CVE List | Through 3.5.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBProcessMaker 3.5.4 - Local File inclusionExploitDB exploitby Ai HoNot analyzed1 file
References
4ExploitDB-50229exploit
https://www.exploit-db.com/exploits/50229 Official Product Homepageproduct
https://www.processmaker.com/ VulnCheck Advisory: ProcessMaker 3.5.4 Local File Inclusion via Path TraversalThird-party advisory
https://www.vulncheck.com/advisories/processmaker-local-file-inclusion-via-path-traversal