216.73.217.22

CVE-2025-0632

· Published 21/04/2025 06:15 · Modified 21/04/2025 14:23

Labels: CVE-2025-0632 2025-04-219c1820ae-fb77-4810-a8aa-ca46e7474d2fCVE-2025-0632CWE-22

Essential information

Published
21/04/2025 06:15
Modified
21/04/2025 14:23
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise. This issue affects Rock Maker Web: from 3.2.1.1 and later

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
9c1820ae-fb77-4810-a8aa-ca46e7474d2f
NVD
View on NVD

Affected products (CPE)

ProductCPE
formulatrix / rock maker web cpe:2.3:a:formulatrix:rock_maker_web:3.2.1.1:*:*:*:*:*:*:*

References