Impact
Improper limitation of a pathname to a restricted directory in the KontrolPanel.exe component of AKINSOFT Wolvox9 ERP allows a path traversal attack. An attacker could supply file paths containing directory separators and navigate outside the intended directory scope, potentially accessing sensitive configuration files, credentials, or system files. This weakness corresponds to CWE-22 and can lead to confidentiality breaches or unauthorized file modification. The vulnerability impacts the local system where the application is installed and does not immediately provide remote code execution capabilities but can be leveraged to gather critical data.
Affected Systems
AKINSOFT Wolvox9 ERP, specifically the KontrolPanel.exe component, from version s26.02.17 up through, but not including, s26.02.22. The affected product is released by AKIN Software Computer Import Export Industry and Trade Ltd.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited observed exploitation. Likely attack vectors include attempts at manipulating the file selection UI or API parameters to supply crafted path inputs. Attackers with local or application‑level access could exploit this weakness to read restricted files, which could lead to further compromise if sensitive data is exposed.
OpenCVE Enrichment