vendor:
ProcessMaker
by:
Ai Ho
8,8
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: ProcessMaker
Affected Version From: ProcessMaker <= 3.5.4
Affected Version To: ProcessMaker <= 3.5.4
Patch Exists: YES
Related CWE: N/A
CPE: a:processmaker:processmaker
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2021
ProcessMaker 3.5.4 – Local File inclusion
ProcessMaker 3.5.4 is vulnerable to Local File Inclusion. An attacker can use curl to send a malicious request to the target server and read the content of the file. The attacker can also use Jaeles Scanner to scan the target server for this vulnerability.
Mitigation:
The user should upgrade to the latest version of ProcessMaker to mitigate this vulnerability.