CVE-2018-20470
sahipro sahi_pro Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2018-20470 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
sahi_proBrowse sahipro / sahi_pro | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBSahi pro 7.x/8.x - Directory TraversalExploitDB exploitby Goutham MadhwarajNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHTyto Sahi pro 7.x/8.x - Local File InclusionCVSS 7.5
Tyto Sahi Pro versions through 7.x.x and 8.0.0 are susceptible to a local file inclusion vulnerability in the web reports module which can allow an outside attacker to view contents of sensitive files.
Impact
Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server.
Remediation
Apply the latest security patches or upgrade to a patched version of Tyto Sahi pro.
Source: ProjectDiscovery