Record summary

CVE-2018-20470 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 28, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBSahi pro 7.x/8.x - Directory TraversalExploitDB exploitby Goutham MadhwarajNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHTyto Sahi pro 7.x/8.x - Local File InclusionCVSS 7.5

Tyto Sahi Pro versions through 7.x.x and 8.0.0 are susceptible to a local file inclusion vulnerability in the web reports module which can allow an outside attacker to view contents of sensitive files.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server.

Remediation

Apply the latest security patches or upgrade to a patched version of Tyto Sahi pro.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2018cvelfipacketstormsahiprovkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:sahipro:sahi_pro:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3