CVE-2021-47978
MEDIUM WAF: High
CVSS 6.2
Published: 2026-05-16
CWE-98
ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting improper path traversal validation. Attackers can send requests with directory traversal sequences to access sensitive system files like /etc/passwd without authentication.
WAF Coverage Analysis
PHP Remote File Inclusion
High WAF Coverage
OWASP: A03:2021 Injection
931xxx - Remote File Inclusion 933xxx - PHP Injection