Path Traversal Vulnerability in PMWeb by PMWeb Inc.
CVE-2026-101082
6.9MEDIUM
What is CVE-2026-101082?
A path traversal vulnerability has been identified in PMWeb versions 7.x, 8.x, and 2025.x, primarily affecting the 'downloader.aspx' file. This vulnerability allows attackers to manipulate file paths through the FullFileName and FileName parameters, potentially leading to unauthorized file access on the server. The exploit can be executed remotely, and the weakness has been publicly disclosed without any response from the vendor upon notification.
Affected Version(s)
PMWeb 7.*
PMWeb 8.*
PMWeb 2025.*
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
aljaber (VulDB User)
aljaber (VulDB User)
VulDB CNA Team
