Formulatrix Rock Maker Web Local File Inclusion Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A Local File Inclusion (LFI) vulnerability has been identified in the Render function of Formulatrix Rock Maker Web (RMW) versions 3.2.1.1 and later. This vulnerability allows remote attackers to execute arbitrary code, potentially leading to the exfiltration of sensitive data such as configuration files and credentials. The lack of rate limiting could also enable attackers to enumerate the filesystem of the host machine, with the possibility of a full host compromise.
Impact
Exploitation of this vulnerability could result in unauthorized access to sensitive data, including configuration files and credentials, and could lead to a complete compromise of the host machine.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
