nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25312 CVE-2018-25312
HIGH
LifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution
Record summary
CVE-2018-25312 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arbitrary locations on the system, enabling remote code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ClearSeaBrowse LifeSize / ClearSea | CVE List | 3.1.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBLifeSize ClearSea 3.1.4 - Directory TraversalExploitDB exploitby rsp3arNot analyzed1 file
References
3ExploitDB-44390exploit
https://www.exploit-db.com/exploits/44390 VulnCheck Advisory: LifeSize ClearSea 3.1.4 Directory Traversal Remote Code ExecutionThird-party advisory
https://www.vulncheck.com/advisories/lifesize-clearsea-directory-traversal-remote-code-execution