Impact
The vulnerability is a path traversal flaw in the file download component of BugTracker.NET. A user-supplied file name parameter is not properly validated, allowing an authenticated remote attacker to supply a manipulated path that resolves to a location outside the intended directory. Successful exploitation lets the attacker read any file that the application process can access, potentially exposing sensitive system data.
Affected Systems
The affected system is BugTracker.NET by BugTracker.NET. All versions of the BugTracker.NET application are listed in the CPE entry, and the advisory does not specify a narrower version range, so the entire product line is at risk.
Risk and Exploitability
This flaw scores a CVSS base of 7.1, indicating a high impact if exploited. Exploitation requires network access to the web interface and valid authentication credentials for the BugTracker.NET application. While the EPSS score is not published, the lack of a CISA KEV listing suggests no widespread exploitation has been reported to date. Nevertheless, the potential for confidential file disclosure warrants prompt mitigation.
OpenCVE Enrichment