Path Traversal Vulnerability in Next4Biz CSM Product
CVE-2026-6377

7.5HIGH

What is CVE-2026-6377?

A Path Traversal vulnerability exists in Next4Biz Information Technologies Inc.'s Customer Service Management (CSM) system, which permits unauthorized access to files and directories stored on the system. This flaw arises from improper limitations on pathname inputs, allowing malicious actors to exploit the system by navigating outside of the intended directories. Users of CSM versions 6.8.9 through 07092026 should be particularly mindful of this issue as it poses significant risks to data integrity and confidentiality.

Affected Version(s)

CSM (Customer Service Management) 6.8.9 <= 07092026

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammet Fatih SENCER
.