Impact
Bold Reports Standalone Report Designer versions prior to 14.1.12 contain a missing path‑validation check in the database download feature. An unauthenticated attacker can supply a crafted request that uses a relative path traversal sequence to read any file on the host filesystem. This allows disclosure of sensitive files, including authentication credentials, which can grant the attacker full, unauthorized access to the application. The flaw is a classic path traversal defect (CWE-22).
Affected Systems
Attackers can target instances of Bold Reports Standalone Report Designer that include the DataHub module, introduced in version 6.3. The vulnerability exists in all releases that contain this module up to and including 14.1.11. Versions before 6.3 are not affected, and upgrading to 14.1.12 or newer eliminates the flaw.
Risk and Exploitability
The CVSS base score of 9.3 signals a severe weakness that can lead to total application compromise. The EPSS score of less than 1 percent indicates that, while exploitation has not been widely observed, the risk remains real. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw without requiring authentication and with only network access to the server, making the overall threat realistic for exposed installations.
OpenCVE Enrichment