PT-2020-14936 · Cellopoint · Cellopoint Cellos
Cyku Hong
·
Published
2020-08-25
·
Updated
2025-05-08
·
CVE-2020-17385
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cellopoint Cellos version 4.1.10 Build 20190922
Description
The issue allows unauthorized users to launch a Path Traversal attack due to improper validation of URL input, enabling access to arbitrary files on the system.
Recommendations
For version 4.1.10 Build 20190922, consider implementing proper URL input validation to prevent Path Traversal attacks. As a temporary workaround, restrict access to sensitive files and directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cellopoint Cellos