7.5
CVSSv2

CVE-2019-15102

Published: 06/09/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Tyto Sahi Pro 6.x up to and including 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an malicious user to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an malicious user to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sahipro sahi pro