Executive brief
The Gotac Police Statistics Database System contains a security flaw that allows unauthorized individuals to access sensitive files on the server. By exploiting this weakness, an attacker could remotely download internal system files without needing a username or password. This could lead to the exposure of confidential police data or system configuration details, potentially compromising the entire database operation.
Technical details
The Gotac Police Statistics Database System (versions up to 1.0.2) is vulnerable to an arbitrary file read flaw. The root cause is an absolute path traversal vulnerability (CWE-36) that fails to properly sanitize user-supplied input used to reference files. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to access and download sensitive system files outside of the intended web directory. Although the CVE was later marked as rejected by the CNA, the initial technical analysis identified a high-severity impact on confidentiality.
Affected products
- Gotac Police Statistics Database System up to 1.0.2
Timeline
- 2026-01-15: disclosed: Initial disclosure by TWCERT/CC
- 2026-01-16: advisory: NVD publication date
- 2026-07-30: other: CVE marked as Rejected by TWCERT/CC