← Vulnerability feed

Vulnerability record · CVE-2019-15102 · published 6 September 2019

CVE-2019-15102: Sahipro sahi pro missing authentication for critical function vulnerability

Sahipro · Sahi Pro

An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.

9.8 CVSS 3.0 Critical EPSS 3.9% · top 10.2% CWE-306 · Missing authentication for critical function
9.8CVSS 3.0 base score, v2 7.5
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-15102 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-13597Sahipro sahi pro os command injection vulnerability_s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one ca…EPSS 14%9.8CVE-2018-20469Sahipro sahi pro sql injection vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can b…EPSS 19%8.8CVE-2018-20468Sahipro sahi pro csv injection vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV inje…EPSS 2.2%7.5CVE-2019-13063Sahipro sahi pro path traversal vulnerabilityWithin Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_…EPSS 27%7.5CVE-2018-20470Sahi Pro web reports module directory traversal allows arbitrary file readTyto Sahi Pro through 7.x.x and 8.0.0 contains a directory traversal (path traversal) flaw in its web reports module, allowing an outside attacker to…EPSS 46%analysed6.1CVE-2019-13066Sahipro sahi pro cross-site scripting vulnerabilitySahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updatin…EPSS 1.00%5.4CVE-2018-20472Sahipro sahi pro cross-site scripting vulnerabilityAn issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.EPSS 2.1%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed

Source: NIST National Vulnerability Database (record CVE-2019-15102), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.