CVE-2026-105157 | RainyGao DocSys up to 2.02.85 Document Controller /Doc/doGetTmpFile.do DocController.doGetTmp path/fileName path traversal (IKA7W8)

SecurityVulns

A vulnerability marked as problematic has been reported in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal.

This vulnerability is referenced as CVE-2026-105157. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More