Boss Mini 1.4.0 Build 6221 contains a file inclusion caused by manipulation of the 'path' argument in boss/servlet/document, letting remote attackers include arbitrary files, exploit requires remote access.
id: CVE-2023-3643
info:
name: CAREL Boss Mini <= 1.4.0 - Local File Inclusion
author: Kazgangap
...