Impact
The vulnerability lies in the handling of the schema_name argument in the RestoreRequest.php API endpoint, enabling an attacker to craft a request that causes the application to traverse directories and access files outside the intended path. This can expose or modify sensitive data. The exploit is remote and requires a high‑complexity attack scenario, but the public exploit is available, indicating that knowledgeable attackers could perform the traversal if they are able to craft the payload.
Affected Systems
The affected product is David‑Crty databasement. Versions up to and including 1.7.1 are vulnerable. A newer release, version 1.7.2, contains the fix and should be deployed to mitigate the issue.
Risk and Exploitability
The CVSS score of 2.1 classifies the impact as low, and there is no EPSS data or KEV listing available. The exploit is considered difficult, yet the publicly available exploit demonstrates that determination and skill can lead to successful exploitation. Path traversal can result in unauthorized file disclosure or data manipulation, potentially affecting the confidentiality and integrity of the system's data stores.
OpenCVE Enrichment