Record summary

CVE-2019-14251 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 14, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHT24 Web Server - Local File InclusionCVSS 7.5

T24 web server is vulnerable to unauthenticated local file inclusion that permits an attacker to exfiltrate data directly from server.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, potentially leading to unauthorized access or information disclosure.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the LFI vulnerability in the T24 Web Server.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscvecve2019temenoslfiunauthvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:temenos:t24:r15.01:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2