Impact
A path traversal flaw in the dbgate exportModelSql function allows an attacker to supply a crafted outputFile argument that the system will resolve to a location outside the intended export directory. By manipulating this parameter, the attacker can write arbitrary files to the target host, potentially overwriting configuration files or creating benign documents. The vulnerability does not explicitly grant code execution but enables unauthorized modification of the filesystem, which can be used to disrupt services or prepare for subsequent attacks.
Affected Systems
The flaw impacts dbgate versions 7.3.1 and earlier. The affected component is packages/api/src/controllers/databaseConnections.js within the Export Handler. Users running these versions are exposed to the path traversal vulnerability.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Although the EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog, a publicly available exploit demonstrates that the vulnerability can be targeted remotely via crafted HTTP requests that trigger the path traversal. The risk is therefore significant for installations that expose the Export Handler to untrusted network traffic, as the ability to write files can lead to data integrity issues and facilitate further lateral movement.
OpenCVE Enrichment