Local File Inclusion in ProcessMaker by ProcessMaker Inc.
CVE-2021-47978
Key Information:
- Vendor
Processmaker
- Status
- Vendor
- CVE Published:
- 16 May 2026
Badges
What is CVE-2021-47978?
ProcessMaker 3.5.4 is prone to a local file inclusion vulnerability that can be exploited by unauthenticated attackers to gain unauthorized access to sensitive files. This vulnerability arises from insufficient validation of path traversal sequences, allowing attackers to manipulate input and access sensitive system files such as /etc/passwd. Successful exploitation could lead to exposure of sensitive information and potential further compromises within the system.
Affected Version(s)
ProcessMaker 0 <= 3.5.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
