Jul 2026
Description
A Local File Inclusion (LFI) vulnerability exists in the affected web application due to insufficient sanitization of user-supplied input in a file path parameter. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files.
Details
- Product: docuForm FSM Server
- Affected Versions: 11.11c
- Vulnerability Type: CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
- Risk Level: Medium - CVSS 3.1: 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
- Vendor URL: www.docuform.de
- Vendor acknowledged vulnerability: Yes
- CVE: CVE-2026-51925
Impact
Successful exploitation of this Local File Inclusion vulnerability allows remote attackers to read arbitrary files on the affected server, potentially exposing sensitive information such as configuration files, user credentials or system data like /etc/passwd.
References
Timeline
- 2025-10: Vulnerability reported to the vendor.
- 2025-11: Vendor published a fix for the issue.
- 2026-06: Information about the vulnerability is published.
Credits
- Bastian Recktenwald (Bastian.Recktenwald@ZeroBreach.de)
