Impact
The vulnerability in Ragic Enterprise Cloud Database allows a privileged remote attacker to perform Relative Path Traversal and read arbitrary system files. This leads to disclosure of sensitive data such as configuration files or credentials, impacting confidentiality. The weakness is a classic file access control flaw identified as CWE-23.
Affected Systems
Vendor Ragic; product Enterprise Cloud Database. The affected versions are not explicitly listed; all deployments of the product remain vulnerable until patched.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. A privileged remote attacker can exploit the flaw by providing a specially crafted path, suggesting that the attack vector is from a remote network. The lack of an EPSS score means the real-world exploitation likelihood is unknown, but the impact remains significant once exploitation is achieved.
OpenCVE Enrichment