GHSA-hcq3-wvr8-3wvgCriticalCVSS 9.8
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation...
🔗 CVE IDs covered (1)
📋 Description
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.
🔗 References (4)
- https://nvd.nist.gov/vuln/detail/CVE-2026-65687
- https://www.boldreports.com/resources/release-history/standalone-report-designer/14-1#14-1-12
- https://www.vulncheck.com/advisories/bold-reports-standalone-report-designer-arbitrary-file-read-via-svg-processing
- https://github.com/advisories/GHSA-hcq3-wvr8-3wvg