Ai3 QbiCRMGateway Arbitrary File Reading Vulnerability via Relative Path Traversal

Vulnerability

A vulnerability allowing arbitrary file reading has been identified in the QbiCRMGateway application developed by Ai3. This issue arises from relative path traversal, which enables unauthenticated remote attackers to download arbitrary system files. The vulnerability affects QbiCRMGateway versions 7.5.1 through 8.5.03.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system files, potentially allowing for further attacks or information disclosure.

Remediation

Users are advised to update QbiCRMGateway to version 8.5.04 or later, or to install the available patch.

Added: Aug 29, 2025, 4:17 AM
Updated: Aug 29, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.