← Vulnerability feed

Vulnerability record · CVE-2019-13063 · published 23 September 2019

CVE-2019-13063: Sahipro sahi pro path traversal vulnerability

Sahipro · Sahi Pro

Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.e., being able to pull any file from the remote victim application). This can be used to steal and obtain sensitive config and other files. This can result in complete compromise of the application. The script parameter is vulnerable to directory traversal and both local and remote file inclusion.

7.5 CVSS 3.1 High EPSS 27% · top 2.0% CWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in file disclosure (i.e., being able to pull any file from the remote victim application). This can be used to steal and obtain sensitive config and other files. This can result in complete compromise of the application. The script parameter is vulnerable to directory traversal and both local and remote file inclusion.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://sahipro.com/downloads-archive/ Vendor Advisory
https://www.exploit-db.com/exploits/47062 ExploitThird Party AdvisoryVDB Entry
https://sahipro.com/downloads-archive/ Vendor Advisory
https://www.exploit-db.com/exploits/47062 ExploitThird Party AdvisoryVDB Entry

Track CVE-2019-13063 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15102Sahipro sahi pro missing authentication for critical function vulnerabilityAn issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication …EPSS 3.9%9.8CVE-2019-13597Sahipro sahi pro os command injection vulnerability_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one ca…EPSS 14%9.8CVE-2018-20469Sahipro sahi pro sql injection vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can b…EPSS 19%8.8CVE-2018-20468Sahipro sahi pro csv injection vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV inje…EPSS 2.2%7.5CVE-2018-20470Sahi Pro web reports module directory traversal allows arbitrary file readTyto Sahi Pro through 7.x.x and 8.0.0 contains a directory traversal (path traversal) flaw in its web reports module, allowing an outside attacker to…EPSS 46%analysed6.1CVE-2019-13066Sahipro sahi pro cross-site scripting vulnerabilitySahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updatin…EPSS 1.00%5.4CVE-2018-20472Sahipro sahi pro cross-site scripting vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.EPSS 2.1%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2019-13063), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.