CVE-2019-13063 describes a directory traversal and file inclusion vulnerability in Sahi Pro 8.0.0. An unauthenticated attacker can exploit this by sending a specially crafted URL to the Script_view page, using the 'script' parameter to disclose arbitrary files from the system. This vulnerability carries a CVSS score of 7.5 (High), indicating that it can be exploited remotely with low complexity, leading to a complete compromise of the application through sensitive file theft. While not actively exploited in the wild (KEV), public exploit code exists on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0CPE matchmatch criteria | cpe:2.3:a:sahipro:sahi_pro:8.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.