Executive brief
PerfreeBlog, a Java-based content management system used for building websites and blogs, contains a security flaw that allows unauthorized users to read sensitive files from the underlying server. By exploiting this vulnerability, an attacker could access configuration files, system credentials, or other private data, potentially leading to a full compromise of the website and its hosting environment. This issue stems from a failure to properly restrict file access permissions within the theme management component.
Technical details
An arbitrary file read vulnerability exists in PerfreeBlog v4.0.11 within the `validThemeFilePath` function. The vulnerability arises because the path validation logic only checks if the requested path contains the `themePath` string, failing to prevent directory traversal sequences like `../`. Furthermore, the `/api/auth/theme/getThemeFileContent` endpoint lacks proper authorization checks (missing `hasPermission` validation), allowing any registered user—or an unauthenticated user in some configurations—to submit a crafted POST request. Attackers can leverage this to read sensitive system files such as `application-prod.yaml` or `/etc/passwd` by manipulating the `themePath` and `path` parameters.
Affected products
- Perfree PerfreeBlog 4.0.11
Timeline
- 2025-10-24: advisory: NVD published the vulnerability report.