Impact
The vulnerability lies in the Author Name Handler component of danpros HTMLy and allows an attacker to manipulate the Name argument in /system/htmly.php to traverse directories. This type of flaw is identified as CWE‑22 and can expose arbitrary files on the server. The CVE description notes that the exploit is available to the public and can be launched remotely, indicating that an attacker need only provide a crafted request to trigger the traversal, potentially revealing sensitive configuration or source code data.
Affected Systems
Version 3.1.1 or earlier of danpros HTMLy is affected. The issue exists in the Author Name Handler – the /system/htmly.php script – which is part of the HTMLy product from the vendor danpros. No other versions or components are listed as impacted in the available data.
Risk and Exploitability
With a CVSS score of 6.9 the issue is considered medium severity. The EPSS score is not provided, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it is not currently known to be widely exploited in the wild. The attack vector is remote, and the exploit requires only an external request containing a malicious Name parameter. The vulnerability can lead to disclosure of files, which may provide attackers with information that could be leveraged in further attacks, such as privilege escalation or information gathering.
OpenCVE Enrichment