Impact
A flaw in the render_slides function of 06ketan slideshot allows an attacker to manipulate the htmlPath argument, resulting in a path traversal vulnerability that can be exploited remotely. This enables the attacker to read arbitrary files on the system where the application is running, potentially exposing sensitive data. The CVSS score of 5.3 indicates a moderate level of severity, and the vulnerability is documented as exploitable with published proof‑of‑concept code.
Affected Systems
The vulnerability affects the 06ketan slideshot product in all versions up to and including 4.4.0. The product is maintained by the 06ketan organization and is listed as a single component in the Common Platform Enumeration space.
Risk and Exploitability
The attack vector is remote, as the vulnerability can be triggered by supplying a crafted htmlPath value to the rendering endpoint. While the EPSS score is not available, the CVSS score of 5.3 reflects a moderate exploitation difficulty. The vulnerability is not yet listed in the CISA KEV catalog, but published exploits suggest it could be actively used. Systems running the affected versions are at risk of local file disclosure, compromising confidentiality and potentially exposing configuration or credential files.
OpenCVE Enrichment