Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-26697 | A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 04 Sep 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Apprain
         Apprain apprain  | 
|
| CPEs | cpe:2.3:a:apprain:apprain:4.0.5:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Apprain
         Apprain apprain  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Thu, 04 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 04 Sep 2025 11:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/download/ allows remote users to bypass the intended SecurityManager restrictions and download any file if they have adequate permissions outside the document root configured on the server via the base64 path after /download/. | |
| Title | Path Traversal vulnerability in appRain CMF | |
| Weaknesses | CWE-22 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-04T14:16:10.456Z
Reserved: 2025-04-16T09:09:29.024Z
Link: CVE-2025-41035
Updated: 2025-09-04T14:16:07.899Z
Status : Analyzed
Published: 2025-09-04T11:15:33.747
Modified: 2025-09-04T18:44:52.747
Link: CVE-2025-41035
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD