PT-2026-85517 · Gfi · Clearview+1
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GFI Exinda AI versions prior to 7.6.5
GFI ClearView versions prior to 7.6.5
Description
A path traversal issue exists in the system maintenance configuration download handler. The
wcf handle download() function fails to sanitize parameters prefixed with v del before appending them to the base configuration directory path. This allows an authenticated attacker with Admin privileges to read arbitrary files from the system with root permissions. Path traversal is a technique used to access files and directories that are stored outside the web root folder.Recommendations
Update GFI Exinda AI to version 7.6.5 or later.
Update GFI ClearView to version 7.6.5 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clearview
Exinda Ai