CVE-2019-14251

HIGH EXPLOITED NUCLEI

Temenos Channels R15.01 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-14251 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

Nuclei Templates (1)

T24 Web Server - Local File Inclusion
HIGHby 0x_Akoko

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0785
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

VulnCheck KEV 2024-01-14
CWE
CWE-22
Status published
Products (1)
temenos/t24 r15.01
Published Dec 09, 2019
Tracked Since Feb 18, 2026