CVE-2025-70841

CRITICAL

Amcoders Dokans - Authentication Bypass

Title source: rule

Description

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credentials, SMTP/SendGrid API credentials, and internal configuration parameters, enabling complete system compromise including authentication bypass via session token forgery, direct database access to all tenant data, and email infrastructure takeover. Due to the multi-tenancy architecture, this vulnerability affects all tenants in the system.

Scores

CVSS v3 10.0
EPSS 0.0009
EPSS Percentile 26.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Classification

CWE
CWE-287
Status published

Affected Products (1)

amcoders/dokans

Timeline

Published Feb 03, 2026
Tracked Since Feb 18, 2026