CVE-2026-51925
8.1docuForm GmbH · Client
A Local File Inclusion vulnerability in docuForm GmbH Client v.11.11c allows remote authenticated attackers to read arbitrary files and execute code.
Executive summary
A Local File Inclusion vulnerability in docuForm GmbH Client version 11.11c permits remote attackers with low privileges to read sensitive server files and potentially execute arbitrary code.
Vulnerability
A Local File Inclusion flaw exists within the dfm-menu_report.php component, requiring low-privileged user authentication and network access to exploit.
Business impact
Successful exploitation of this vulnerability can lead to severe data compromise, including unauthorized access to sensitive configuration files, source code, and core system files. With a CVSS score of 8.1, the high severity rating reflects the potential for total confidentiality and integrity loss on the affected server, increasing organizational risk.
Remediation
Immediate Action: Contact docuForm GmbH to obtain and apply the official security update or patch for version 11.11c.
Proactive Monitoring: Monitor server access logs for anomalous HTTP requests targeting the dfm-menu_report.php component or unusual file access patterns.
Compensating Controls: Implement Web Application Firewall rules to inspect and block traversal sequences within parameters passed to the vulnerable component.
Exploitation status
Public Exploit Available: No (no confirmed public exploit or weaponized module currently available in the telemetry).
Analyst recommendation
Security teams must prioritize addressing this high-severity flaw by engaging the vendor for mitigation guidance. Until a formal patch is deployed, administrators should restrict access to the affected endpoint and enforce strict monitoring on the server environment.