CVE-2019-18870

MEDIUM

Blaauw Remote Kiln Control <v3.00r4 - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.

Scores

CVSS v3 6.5
EPSS 0.0073
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
blaauwproducts/remote_kiln_control 3.0.0 (2 CPE variants)
blaauwproducts/remote_kiln_control < 3.0.0
Published May 07, 2020
Tracked Since Feb 18, 2026