5
CVSSv2

CVE-2018-20470

Published: 17/06/2019 Updated: 30/01/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Tyto Sahi Pro up to and including 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside malicious user to view contents of sensitive files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sahipro sahi pro

Exploits

# Exploit Title: Sahi pro ( <= 8x ) Directory traversal # Date: 17-06-2019 # Exploit Author: Goutham Madhwaraj ( barrierseccom ) # Vendor Homepage: sahiprocom/ # Software Link: sahiprocom/downloads-archive/ # Version: 7x , <= 8x # Tested on: Windows 10 # CVE : CVE-2018-20470 Description : An issue was discover ...
Sahi Pro versions 7x and 8x suffer from a directory traversal vulnerability ...