Description
Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise.

This issue affects Rock Maker Web: from 3.2.1.1 and later
Published: 2025-04-21
Score: 9.2 Critical
EPSS: 2.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Apply the official security patch provided by Rock Maker or update provided by Formulatrix. If immediate patching is not feasible: * Restrict external access to RMW from the public internet via firewall rules * Use network segmentation to limit RMW access only to internal trusted users * Monitor access logs for suspicious URL patterns such as ../ or unusual GET requests.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12383 Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise. This issue affects Rock Maker Web: from 3.2.1.1 and later
History

Mon, 28 Apr 2025 03:00:00 +0000


Mon, 21 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Apr 2025 05:45:00 +0000

Type Values Removed Values Added
Description Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise. This issue affects Rock Maker Web: from 3.2.1.1 and later
Title Local File Inclusion (LFI) leading to sensitive data exposure
Weaknesses CWE-22
CWE-98
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: MON-CSIRT

Published:

Updated: 2025-04-28T02:49:47.566Z

Reserved: 2025-01-22T02:10:16.044Z

Link: CVE-2025-0632

cve-icon Vulnrichment

Updated: 2025-04-21T13:44:12.335Z

cve-icon NVD

Status : Deferred

Published: 2025-04-21T06:15:44.043

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-0632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses