PT-2026-85518 · Gfi · Gfi Clearview+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GFI Exinda AI versions prior to 7.6.5
GFI ClearView versions prior to 7.6.5
Description
A path traversal issue exists in the diagnostic file deletion handler. The
unlink or email file() function processes parameters prefixed with v file row and appends their values to a base directory path without sanitizing for directory traversal sequences. This allows an authenticated attacker with Admin privileges to delete arbitrary files from the system with root permissions.Recommendations
Update GFI Exinda AI to version 7.6.5 or later.
Update GFI ClearView to version 7.6.5 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gfi Clearview
Gfi Exinda Ai