Formulatrix Rock Maker Web Local File Inclusion Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A Local File Inclusion (LFI) vulnerability has been identified in the Render function of Formulatrix Rock Maker Web (RMW) versions 3.2.1.1 and later. This vulnerability allows remote attackers to execute arbitrary code, potentially leading to the exfiltration of sensitive data such as configuration files and credentials. The lack of rate limiting could also enable attackers to enumerate the filesystem of the host machine, with the possibility of a full host compromise.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive data, including configuration files and credentials, and could lead to a complete compromise of the host machine.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.