vendor:
Sahi Pro
by:
Goutham Madhwaraj
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: Sahi Pro
Affected Version From: 7.x.x
Affected Version To: 8.0.0
Patch Exists: YES
Related CWE: CVE-2018-20470
CPE: a:sahi_technologies:sahi_pro
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
Sahi pro ( <= 8.x ) Directory traversal
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.
Mitigation:
Ensure that the web reports module is not accessible from outside the network and that access to sensitive files is restricted.