Executive brief
Next4Biz CSM is a customer service management platform used by organizations to manage support operations. A path traversal vulnerability allows attackers to access files and directories outside of the intended restricted areas, potentially exposing sensitive configuration files, customer data, or internal system files. This could lead to unauthorized access to confidential business information or customer details.
Technical details
A path traversal vulnerability exists in Next4Biz CSM due to improper validation of pathname inputs, allowing attackers to escape directory restrictions using traversal sequences (e.g., ../). The vulnerability affects CSM versions 6.8.9 through 8.0.2 and is network-accessible without requiring authentication. An attacker can exploit this to read arbitrary files from the server filesystem, potentially accessing sensitive configuration files containing credentials or customer data. Patched versions starting from 8.0.3 have addressed this issue.
Affected products
- Next4Biz Information Technologies Inc. CSM (Customer Service Management) 6.8.9 before 8.0.3
Timeline
- 2026-09-07: disclosed