Impact
Bold Reports Standalone Report Designer before version 14.1.12 contains a missing filepath validation flaw in its SVG processing feature that allows an attacker to supply a specially crafted request a classic path traversal weakness that can expose sensitive configuration files or authentication data, effectively granting the attacker full unauthorized access to the application’s backend. The impact is a breach of confidentiality and could serve as a stepping stone to further compromise of the system.
Affected Systems
The affected vendor and product are Bold Reports (By SyncFusion) Standalone Report Designer. Versions prior to 14.1.12 are vulnerable, and the flaw exists only in releases that include the DataHub module introduced from Bold Reports 6.3 onward. Earlier releases before 6.3 are not affected.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of active exploitation at present, yet the CVSS score of 9.3 still reflects a severe risk should exploitation occur. The flaw is unauthenticated and is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by sending a crafted request to the SVG processing endpoint, allowing them to read arbitrary files from the server filesystem without authentication.
OpenCVE Enrichment