Impact
Formwork before version 2.3.13 contains a path traversal flaw in the BackupController that allows authenticated panel users with backup download or delete permission to read or delete arbitrary files outside the backup directory. The attacker can supply a base64‑encoded backslash‑separated traversal payload that bypasses PHP's basename on Linux, enabling access to files that should remain protected. The primary impact of this vulnerability is the possible compromise of confidentiality and integrity of system files due to unauthorized file disclosure or deletion, as identified by CWE-22.
Affected Systems
The vulnerability affects installations of Formwork prior to version 2.3.13. All users running any older version of the getformwork:formwork product are potentially vulnerable. Only newer releases that include the fix are safe.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. Exploitation requires user authentication and specific backup permissions, so it is not an unauthenticated remote code execution but still significant due to the ability to read or delete arbitrary files. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers who obtain backup download or delete rights can craft a payload that bypasses normal file restrictions, making the risk notable for systems where backup permissions are widely granted.
OpenCVE Enrichment