Impact
The flaw is a path‑traversal bug triggered by manipulating the oldfile argument in the add_content function of danpros HTMLy’s Admin Content Endpoint. Exploitation allows an attacker to read arbitrary files on the host, potentially exposing configuration files, sensitive data, or revealing system credentials. The vulnerability is defined by CWE‑22 and is typically exploited from an external network, resulting in confidentiality loss.
Affected Systems
danpros HTMLy versions up to and including 3.1.1 are affected, specifically the Admin Content Endpoint component located in /system/admin/admin.php.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS information is available and the vulnerability is not listed in the CISA KEV catalog, yet the exploit code has already been released publicly. Because the attack can be initiated remotely and no vendor fix is currently available, the risk is tangible for organizations running vulnerable instances. Employing network controls or awaiting an official patch should be prioritized.
OpenCVE Enrichment