← Vulnerability feed

Vulnerability record · CVE-2018-20470 · published 17 June 2019

CVE-2018-20470: Sahi Pro web reports module directory traversal allows arbitrary file read

Sahipro · Sahi Pro

Tyto Sahi Pro through 7.x.x and 8.0.0 contains a directory traversal (path traversal) flaw in its web reports module, allowing an outside attacker to read the contents of sensitive files. Because the reports module is web-exposed and the flaw requires no authentication or user interaction, any reachable instance is at risk of file disclosure.

7.5 CVSS 3.1 High EPSS 46% · top 1.2% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file read with public exploit code and high EPSS, though no KEV listing or confirmed active exploitation.

What it is

Tyto Sahi Pro through 7.x.x and 8.0.0 contains a directory traversal (path traversal) flaw in its web reports module, allowing an outside attacker to read the contents of sensitive files. Because the reports module is web-exposed and the flaw requires no authentication or user interaction, any reachable instance is at risk of file disclosure.

Impact

An attacker gains read access to files on the host that the Sahi Pro service can reach, exposing configuration, credentials or other sensitive data. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached over the network via the web reports module (AV:N, PR:N, UI:N), so no authentication or user interaction is needed. The description does not specify the exact request path or parameter, so the precise entry point is not documented in this record.

Exploitation

Public exploit references exist (Packet Storm and BarrierSec entries tagged Exploit), and EPSS is 0.4606 (98.8th percentile), indicating elevated likelihood; the CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Upgrade Sahi Pro past 8.0.0 to a fixed release; the record does not name a patched version, so confirm with the vendor.
  • If patching is not possible, restrict network access to the web reports module to trusted hosts only.
  • Run the Sahi Pro service with least privilege so readable files are limited.
  • Place the reports module behind an authenticating reverse proxy or WAF that normalizes and blocks traversal sequences.

Detection

  • Inspect web server and Sahi Pro logs for requests containing ../ or encoded traversal sequences against the reports module.
  • Alert on report requests referencing absolute paths or files outside the expected reports directory.
  • Monitor for unusual reads of sensitive files (config, credential stores) by the Sahi Pro process.
  • Baseline normal report URLs and flag deviations in path parameters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-20470 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15102Sahipro sahi pro missing authentication for critical function vulnerabilityAn issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication …EPSS 3.9%9.8CVE-2019-13597Sahipro sahi pro os command injection vulnerability_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one ca…EPSS 14%9.8CVE-2018-20469Sahipro sahi pro sql injection vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can b…EPSS 19%8.8CVE-2018-20468Sahipro sahi pro csv injection vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV inje…EPSS 2.2%7.5CVE-2019-13063Sahipro sahi pro path traversal vulnerabilityWithin Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_…EPSS 27%6.1CVE-2019-13066Sahipro sahi pro cross-site scripting vulnerabilitySahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updatin…EPSS 1.00%5.4CVE-2018-20472Sahipro sahi pro cross-site scripting vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.EPSS 2.1%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2018-20470), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.