Junglewise Threat Intelligence

CVE-2021-47978: ProcessMaker local file inclusion via path traversal

CVE-2021-47978 · Severity: medium · CVSS 6.2 · Published 2026-05-16

Executive brief

ProcessMaker, a business process automation platform used to manage corporate workflows, contains a security flaw that allows unauthorized individuals to view sensitive system files. By sending specially crafted web requests, an attacker can bypass security checks to read internal configuration files or user data. This could lead to the exposure of administrative credentials or other confidential information, potentially compromising the entire automation environment.

Technical details

A local file inclusion (LFI) vulnerability exists in ProcessMaker versions up to and including 3.5.4 due to improper validation of user-supplied paths. An unauthenticated attacker can exploit this by sending HTTP requests containing directory traversal sequences (e.g., '../../../../etc/passwd') to the web server. This allows for the unauthorized retrieval of sensitive files from the underlying operating system. The vulnerability is rooted in improper control of filenames for include/require statements in the PHP-based application (CWE-98). While some CVSS vectors suggest a local attack vector, the nature of the exploit via curl against a target IP indicates it is reachable over the network.

Affected products

  • ProcessMaker ProcessMaker <= 3.5.4

Timeline

  • 2021-04-16: disclosed: Vulnerability discovered by researcher Ai Ho
  • 2021-08-26: other: Public exploit published on Exploit-DB
  • 2026-05-16: advisory: CVE published and NVD record created

References