Impact
The vulnerability in DocSys version 2.02.80 permits an attacker to retrieve any file stored on the server through the downloadDocEx.do endpoint without authentication. By manipulating the targetPath parameter, the attacker can bypass all security checks and access files that could contain confidential data, configuration files, or code. The weakness corresponds to improper access control, allowing unauthorized disclosure of information.
Affected Systems
DocSys 2.02.80 is affected. No specific vendor is listed. The vulnerability exists in the download functionality of this version and any older versions that have not yet been patched.
Risk and Exploitability
The attack requires only a simple HTTP request; no credentials are needed, which means exploitation is straightforward for anyone with network access to the server. Although no EPSS score is available and the vulnerability is not in the CISA KEV catalog, the lack of authentication combined with the potential for data leakage means the risk is high for organisations that host sensitive documents.
OpenCVE Enrichment