PT-2025-35906 · Unknown · Apprain Cmf
Rafael Pedrero
·
Published
2025-09-04
·
Updated
2025-09-04
·
CVE-2025-41035
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
appRain CMF version 4.0.5
Description
An authenticated Path Traversal vulnerability exists in the
/apprain/common/download/ endpoint. This allows remote users to bypass SecurityManager restrictions and download arbitrary files if they possess sufficient permissions outside the configured document root. The vulnerability is triggered by manipulating the base64 encoded path following /download/.Recommendations
Ensure that access to the
/apprain/common/download/ endpoint is restricted to authorized users only.
Validate and sanitize the base64 encoded path input to prevent path traversal attempts.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apprain Cmf