This issue affects Rock Maker Web: from 3.2.1.1 and later
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Apply the official security patch provided by Rock Maker or update provided by Formulatrix. If immediate patching is not feasible: * Restrict external access to RMW from the public internet via firewall rules * Use network segmentation to limit RMW access only to internal trusted users * Monitor access logs for suspicious URL patterns such as ../ or unusual GET requests.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12383 | Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise. This issue affects Rock Maker Web: from 3.2.1.1 and later |
Mon, 28 Apr 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 21 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Apr 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise. This issue affects Rock Maker Web: from 3.2.1.1 and later | |
| Title | Local File Inclusion (LFI) leading to sensitive data exposure | |
| Weaknesses | CWE-22 CWE-98 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: MON-CSIRT
Published:
Updated: 2025-04-28T02:49:47.566Z
Reserved: 2025-01-22T02:10:16.044Z
Link: CVE-2025-0632
Updated: 2025-04-21T13:44:12.335Z
Status : Deferred
Published: 2025-04-21T06:15:44.043
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-0632
No data.
OpenCVE Enrichment
No data.
EUVD