Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2020-08-25T07:35:18.510246Z

Updated: 2024-09-17T03:38:07.532Z

Reserved: 2020-08-07T00:00:00

Link: CVE-2020-17385

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-08-25T08:15:10.550

Modified: 2020-08-27T20:17:18.397

Link: CVE-2020-17385

cve-icon Redhat

No data.