Metrics
Affected Vendors & Products
Sat, 29 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Volmarg
Volmarg personal Management System |
|
| Vendors & Products |
Volmarg
Volmarg personal Management System |
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against a permitted base directory, enabling attackers to retrieve sensitive files accessible to the PHP-FPM worker process without using directory traversal sequences. | |
| Title | Volmarg Personal Management System Path Traversal via get-file Endpoint | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T02:57:39.410Z
Reserved: 2026-04-13T20:29:02.810Z
Link: CVE-2026-40526
Updated: 2026-08-29T02:57:34.160Z
Status : Received
Published: 2026-08-27T17:18:22.833
Modified: 2026-08-29T03:17:06.110
Link: CVE-2026-40526
No data.
OpenCVE Enrichment
Updated: 2026-08-27T17:45:04Z