CVE-2020-11431
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- inetsoftware/clear reports · inetsoftware/helpdesk · inetsoftware/pdfc
- Source
- cve@mitre.org
References
- https://www.inetsoftware.de/documentation/clear-reports/release-notes/releases/changes_19.2Release Notes, Vendor Advisory
- https://www.inetsoftware.de/support/news/i-net-clear-reports-security-advisory-2020-apr-06Patch, Vendor Advisory
- https://www.inetsoftware.de/support/news/i-net-helpdesk-sicherheitsankuendigung-2020-apr-06Vendor Advisory
- https://www.inetsoftware.de/support/news/i-net-pdfc-security-advisory-2020-apr-06Patch, Vendor Advisory
- https://www.inetsoftware.de/documentation/clear-reports/release-notes/releases/changes_19.2Release Notes, Vendor Advisory
- https://www.inetsoftware.de/support/news/i-net-clear-reports-security-advisory-2020-apr-06Patch, Vendor Advisory
- https://www.inetsoftware.de/support/news/i-net-helpdesk-sicherheitsankuendigung-2020-apr-06Vendor Advisory
- https://www.inetsoftware.de/support/news/i-net-pdfc-security-advisory-2020-apr-06Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.