PT-2026-39201 · Unknown · Solidcam-Gppl-Ide
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SolidCAM-GPPL-IDE versions 1.0.0 through 1.0.1
Description
The
GpplDocumentLinkHandler resolves the filename directive in GPPL postprocessor files into clickable links. The handler accepts arbitrary absolute, relative, UNC, and subfolder paths, calling File.Exists to determine if a link should be rendered. This allows for information disclosure through path probing and NTLM hash leaks via UNC path probing.Recommendations
Update to version 1.0.2.
Exploit
Fix
Path traversal
SSRF
Information Disclosure
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solidcam-Gppl-Ide