PT-2026-63999 · Bold Reports+1 · Standalone Report Designer
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bold Reports Standalone Report Designer versions 6.3 through 14.1.11
Description
A missing filepath validation issue exists in the database download feature within the DataHub module. This path traversal weakness allows unauthenticated attackers to read arbitrary files from the server filesystem by sending a crafted request, potentially disclosing sensitive information such as authentication credentials and enabling unauthorized application access.
Recommendations
Update Bold Reports Standalone Report Designer to version 14.1.12.
Restrict access to the DataHub module to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Standalone Report Designer