Impact
DocSys version 2.02.80 includes a flaw in the downloadDocEx.do interface that allows an attacker to download any file stored on the server by manipulating the targetPath parameter. Because the endpoint is not protected by authentication or proper access checks, the vulnerability can be exploited to reveal confidential documents, configuration files, or source code. The weakness is characterized by inadequate file permissions (CWE‑552).
Affected Systems
DocSys 2.02.80 is affected. No specific vendor is listed, and the issue arises only in this version of the software. Earlier releases that have not been patched may also be vulnerable if they include the same downloadDocEx.do functionality.
Risk and Exploitability
Exploitation requires only a straightforward HTTP request and does not need credentials, so the operation is trivial for anyone with network access to the target server. The EPSS score of < 1 % indicates a very low but non‑zero exploitation probability, while the CVSS score of 7.5 reflects high severity. The vulnerability is not listed in the CISA KEV catalog. The combination of unauthenticated access and the potential for data leakage makes this risk significant, especially for organizations hosting sensitive documents.
OpenCVE Enrichment