PT-2026-63998 · Bold Reports+1 · Standalone Report Designer
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bold Reports Standalone Report Designer versions 6.3 through 14.1.11
Description
A missing filepath validation in the font processing feature of the DataHub module allows unauthenticated attackers to read arbitrary files from the server filesystem via a crafted request. This path traversal weakness can be used to disclose sensitive server files, such as authentication credentials, potentially leading to full unauthorized access to the application.
Recommendations
Update Bold Reports Standalone Report Designer to version 14.1.12.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Standalone Report Designer