ProcessMaker Local File Inclusion Vulnerability

Vulnerability

A local file inclusion vulnerability has been identified in ProcessMaker version 3.5.4. This vulnerability allows unauthenticated attackers to read arbitrary files by exploiting improper validation of file paths. Attackers can send requests that include directory traversal sequences to access sensitive system files, such as /etc/passwd, without needing authentication.

Impact

Exploitation of this vulnerability allows for local file inclusion, where an attacker can read arbitrary files on the server. This could lead to the disclosure of sensitive information, such as password files or application configuration files.

Reproduction

The vulnerability can be reproduced by sending a request to the ProcessMaker application with directory traversal sequences in the URL. This can be done using a tool like curl or the Jaeles scanner. The request should include the traversal sequences needed to access the desired file, such as /etc/passwd.

Added: May 16, 2026, 4:20 PM
Updated: May 16, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.8
exploitability
8.0
remediation
0.0
relevance
8.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.