PT-2026-64000 · Bold Reports+1 · Standalone Report Designer
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bold Reports Standalone Report Designer versions 6.3 through 14.1.11
Description
A missing filepath validation issue exists in the file upload functionality within the DataHub module. Authenticated attackers can use a crafted filename to perform path traversal, allowing them to access directories outside the intended scope and execute arbitrary commands with high privileges on the server.
Recommendations
Update Bold Reports Standalone Report Designer to version 14.1.12.
Restrict access to the DataHub module to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Standalone Report Designer