A vulnerability was found in ProcessMaker up to 3.5.4 . It has been classified as problematic . Impacted is an unknown function. This manipulation causes improper control of filename for include/require statement in php program ('php remote file inclusion'). The identification of this vulnerability is CVE-2021-47978 . The attack can only be executed locally. Furthermore, there is an exploit available.