Impact
A directory traversal flaw exists in Next4Biz Information Technologies Inc. CSM (Customer Service Management) that allows an attacker to reference files outside the intended directory. The vulnerability can be triggered by manipulating path inputs, potentially giving an attacker the ability to read sensitive files or local configuration data. No injection or code execution vector is explicitly disclosed, so the impact is confined to confidentiality and integrity of exposed files.
Affected Systems
Next4Biz Information Technologies Inc. Customer Service Management version 6.8.9 through the build dated 07092026 are impacted. All installations within this version range are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, indicating that current exploit activity is unknown. The vulnerability is likely exploitable over the network through the web interface of CSM, as path parameters are user‑controllable. Without a vendor response or official fix, the risk remains significant for exposed deployments.
OpenCVE Enrichment