DM Corporative CMS Absolute Path Disclosure Vulnerability

Vulnerability

An absolute path disclosure vulnerability exists in DM Corporative CMS versions prior to 2025.01. This vulnerability allows an attacker to view the contents of the webroot/file directory by navigating to a non-existent file.

Impact

Exploitation of this vulnerability leads to unauthorized disclosure of the server's file system path, which could be used in further attacks.

Remediation

Users can upgrade to DM Corporative CMS version 2025.01 to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.