Impact
DocuForm GmbH Client 11.11c contains a Local File Inclusion flaw in the dfm-menu_report.php component. This weakness allows a remote attacker to supply arbitrary file paths that the server directly includes. If the included file contains PHP code, it will be executed, enabling full remote code execution. The vulnerability can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
Only docuForm GmbH Client version 11.11c is listed as impacted. No other versions or products are referenced in the advisory, so the scope is limited to this specific release.
Risk and Exploitability
The likely attack vector is a crafted HTTP request to the dfm-menu_report.php endpoint with a manipulated filename parameter. This inference comes from the description that a remote attacker can supply arbitrary file paths. The CVSS score of 8.1 indicates high severity. The EPSS score of below 1 % suggests low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Attackers do not need privileged access; remote network access to the server hosting the client suffices, and any file path that the web server can read can be exposed or executed.
OpenCVE Enrichment