Sceawere
Vulnerability Detail
CVE-2026-105157UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RainyGao DocSys Path Traversal
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 5h ago
- Vendor
- RainyGao
- Product
- DocSys
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-04T15:16:30.947Z",
"pubdate": "2026-10-04T15:16:30.947Z",
"executiveSummary": "A critical path traversal vulnerability has been identified in RainyGao DocSys up to version 2.02.85.\nThe vulnerability resides in the DocController.doGetTmp function, which processes file retrieval requests via the /Doc/doGetTmpFile.do endpoint.\nBy manipulating the path or fileName arguments, an unauthenticated remote attacker can bypass file system restrictions to access unauthorized files on the underlying server.\nSuccessful exploitation allows for arbitrary file reading, potentially leading to the exposure of sensitive configuration files, system credentials, or source code.\nThe vulnerability is remotely exploitable, requiring no prior authentication, and exploits have been publicly disclosed, significantly increasing the risk to affected deployments.\nThe vendor has been notified through issue reporting but has not provided a patch, leaving systems vulnerable to active exploitation.",
"technicalDetails": "The vulnerability is rooted in an improper neutralization of special elements used in pathnames within the DocController.doGetTmp function. The application fails to adequately sanitize or validate user-supplied input provided to the 'path' and 'fileName' arguments during file retrieval requests via /Doc/doGetTmpFile.do.\nThe root cause is a lack of input validation regarding directory traversal sequences (such as '../') before the application uses these parameters to construct a file path for local system access.\nAn attacker can exploit this by crafting a malicious HTTP request that incorporates traversal sequences into the 'path' or 'fileName' parameters. When the DocController.doGetTmp function processes these parameters, the underlying file system API resolves the path outside of the intended directory.\nThe attack flow proceeds as follows: 1) The attacker initiates a GET request to the /Doc/doGetTmpFile.do endpoint. 2) The attacker injects traversal sequences into the request parameters (e.g., ?path=../../../../etc/passwd). 3) The backend server processes the input without validation, traversing the directory structure to locate files outside the web root. 4) The application reads the contents of the target file and returns it in the HTTP response, effectively bypassing intended access controls.\nThis vulnerability is classified as a Path Traversal (CWE-22) issue. It is particularly severe because the component allows for remote, unauthenticated access. The post-exploitation impact includes the potential for significant information disclosure. Attackers may retrieve sensitive data, including configuration files containing database credentials, environment variables, or private application data, which may facilitate further exploitation of the host system.\nAffected versions include all releases of RainyGao DocSys up to and including 2.02.85. Given the lack of a vendor-supplied patch, the system remains exposed to any actor capable of reaching the web interface."
}