Impact
A path traversal flaw exists in the DocController.doGetTmp function of RainyGao DocSys, enabling attackers who can modify the 'path' or 'fileName' parameters in requests to /Doc/doGetTmpFile.do to read arbitrary files on the server. This remote exploitation can expose sensitive configuration data and credentials, compromising confidentiality. The issue is identified as CWE‑22 and carries a CVSS score of 5.3, indicating moderate severity.
Affected Systems
The vulnerability affects RainyGao DocSys up to and including version 2.02.85. Any installation of the document controller component exposed through /Doc/doGetTmpFile.do is potentially susceptible.
Risk and Exploitability
With a CVSS score of 5.3 the risk is moderate, and while an EPSS score is not available, the flaw has been publicly disclosed and could be actively exploited. Attackers only need network access to the vulnerable endpoint; no local privileges are required. The vulnerability is not listed in CISA KEV, but its public disclosure and remote exploitation path emphasize the need for timely mitigation.
OpenCVE Enrichment