Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bold Reports
Bold Reports standalone Report Designer |
|
| Vendors & Products |
Bold Reports
Bold Reports standalone Report Designer |
|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full unauthorized access to the application. | |
| Title | Bold Reports Standalone Report Designer 14.1.12 Arbitrary File Read via SVG Processing | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-23T15:37:04.041Z
Reserved: 2026-07-22T20:26:09.979Z
Link: CVE-2026-65687
Updated: 2026-07-23T15:36:58.753Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T20:09:48Z