aytechnet DyaPress ERP/CRM Path Traversal Vulnerability Leading to PHP Local File Inclusion

Vulnerability

A path traversal vulnerability allowing PHP local file inclusion has been identified in aytechnet DyaPress ERP/CRM versions through 18.0.2.0. This vulnerability arises from improper limitations on pathname navigation, potentially enabling malicious actors to include and execute local files on the server.

Impact

Exploitation of this vulnerability could allow an attacker to include local files from the target server, with the included file's content being displayed on the screen. This could lead to the exposure of sensitive information, such as database credentials, which might allow for a complete takeover of the database, depending on the server's configuration.

Remediation

Users are advised to update to a version of DyaPress ERP/CRM later than 18.0.2.0. Patchstack has issued a virtual patch that automatically mitigates this vulnerability for WordPress users.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.