Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.091
EPSS Ranking 92.6%