Impact
A missing filepath validation vulnerability in the file upload feature of Bold Reports Standalone Report Designer allows attackers to supply a crafted filename that traverses outside the intended directory and cause the server to execute arbitrary commands with the privileges of the underlying process. The flaw is confined to the DataHub module introduced in Bold Reports 6.3, so installations prior to 6.3 are unaffected.
Affected Systems
Bold Reports Standalone Report Designer (By SyncFusion) versions prior to 14.1.12 that include the DataHub module (introduced in Bold Reports 6.3) are vulnerable. Versions released before 6.3 do not contain the DataHub module and are not impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of <1% indicates a low statistical probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the file upload function. An attacker with legitimate but potentially untrusted credentials can upload a crafted file name, causing the server to execute arbitrary commands with high privileges. The risk is confined to systems running the vulnerable module and having valid usernames and passwords, implying that strong authentication controls are a primary mitigator.
OpenCVE Enrichment