PT-2026-41464 · Processmaker · Processmaker

Ai Ho

·

Published

2026-05-16

·

Updated

2026-05-16

·

CVE-2021-47978

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without authentication.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-47978

Affected Products

Processmaker