← Vulnerability feed

Vulnerability record · CVE-2020-25134 · published 25 September 2020

CVE-2020-25134: Observium path traversal vulnerability

Observium · Observium

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /settings/?format=../ URIs to pages/settings.inc.php.

8.8 CVSS 3.1 High EPSS 3.4% · top 11.7% CWE-22 · Path traversalCWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusion due to the fact that there is an unrestricted possibility of loading any file with an inc.php extension. Inclusion of other files (even though limited to the mentioned extension) can lead to Remote Code Execution. This can occur via /settings/?format=../ URIs to pages/settings.inc.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-25134 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-25147Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.4%9.8CVE-2020-25132Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.6%8.8CVE-2020-25143Observium sql injection vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is po…EPSS 1.2%8.8CVE-2020-25144Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25145Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25149Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.2%8.8CVE-2020-25136Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 3.0%8.8CVE-2020-25133Observium path traversal vulnerabilityAn issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory traversal and local file inclusio…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2020-25134), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.