RainyGao DocSys Path Traversal Vulnerability in File Deletion Functionality

Vulnerability

A path traversal vulnerability has been identified in RainyGao DocSys versions through 2.02.36. The issue arises in the file '/Doc/deleteDoc.do', where manipulation of the 'path' argument can lead to unauthorized file deletion on the server. This vulnerability can be exploited remotely, and a public proof-of-concept exploit is available.

Impact

Exploitation of this vulnerability allows for arbitrary file deletion on the server.

Reproduction

To reproduce this vulnerability, send a request to the '/Doc/deleteDoc.do' endpoint with a crafted 'path' argument that exploits the path traversal flaw. This can be done by including directory traversal sequences in the 'path' argument to navigate outside of the intended directory and delete arbitrary files on the server.

Added: Oct 12, 2025, 8:18 AM
Updated: Oct 12, 2025, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.