CVE-2019-15102
This allow an attacker to execute an arbitrary script on the remote Sahi Pro server.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.85%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.85% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- sahipro/sahi pro
- Source
- cve@mitre.org
References
- https://barriersec.com/2019/08/cve-2019-15102-sahi-pro/Exploit, Third Party Advisory
- https://barriersec.com/2019/08/cve-2019-15102-sahi-pro/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.