Census CSWeb Path Traversal Vulnerability Allowing Arbitrary File Access

Vulnerability

A path traversal vulnerability has been identified in Census CSWeb version 8.0.1. This issue allows remote, authenticated attackers to input arbitrary file paths, potentially accessing unintended file directories. The vulnerability arises from unsanitized file path inputs that enable directory traversal, such as using '../' to navigate outside of intended directories. Exploitation of this vulnerability could lead to the disclosure of sensitive files, including configuration files and secrets.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive server-side files, such as configuration files that may contain secrets like the application secret.

Reproduction

The vulnerability can be reproduced by sending a request with an arbitrary file path input that includes traversal sequences, such as '../', to access files outside of the intended directory. This can be done by an authenticated user.

Remediation

Users can upgrade to Census CSWeb version 8.1.0 alpha to address this vulnerability.

Added: Mar 23, 2026, 10:51 PM
Updated: Mar 23, 2026, 10:51 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.6
remediation
0.0
relevance
4.6
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.