Vulnerability record · CVE-2020-13158 · published 22 June 2020
CVE-2020-13158: Artica Proxy directory traversal in fw.progrss.details.php popup parameter
AArticatech · Artica Proxy
Artica Proxy Community Edition before 4.30.000000 is vulnerable to directory traversal through the popup parameter of fw.progrss.details.php. An unauthenticated remote attacker can read files outside the intended web directory, exposing configuration data and other sensitive content. The flaw is a classic path traversal (CWE-22) with a high confidentiality impact.
Description
Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal via the fw.progrss.details.php popup parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote file read with a high EPSS score and public exploit code, though no confirmed in-the-wild campaign is documented.
What it is
Artica Proxy Community Edition before 4.30.000000 is vulnerable to directory traversal through the popup parameter of fw.progrss.details.php. An unauthenticated remote attacker can read files outside the intended web directory, exposing configuration data and other sensitive content. The flaw is a classic path traversal (CWE-22) with a high confidentiality impact.
Impact
An attacker gains read access to arbitrary files on the server, which can expose credentials, configuration and other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP against fw.progrss.details.php; the CVSS vector shows no privileges required and no user interaction, so the endpoint is exposed to unauthenticated requests.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.53973, ~99th percentile) and public exploit code is referenced on GitHub, indicating practical exploitation is likely.
What to do
- Upgrade Artica Proxy Community Edition to 4.30.000000 or later.
- If patching is not immediately possible, restrict network access to the Artica Proxy management interface to trusted hosts.
- Validate and sanitize the popup parameter, rejecting traversal sequences and absolute paths.
- Run the web service with least privilege and confine it to a directory so traversal cannot reach sensitive files.
Detection
- Monitor web logs for requests to fw.progrss.details.php containing traversal sequences such as ../ or encoded variants.
- Alert on access to files outside the Artica web root from the proxy process.
- Review outbound or local file reads by the web user for unexpected paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/InfoSec4Fun/CVE-2020-13158 | ExploitThird Party Advisory |
| https://github.com/InfoSec4Fun/CVE-2020-13158 | ExploitThird Party Advisory |
Track CVE-2020-13158 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13158), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.