Sahipro is a narrowly scoped test automation and web application testing platform concentrated in a single product offering, Sahi Pro, that serves a specialized but present role in enterprise quality assurance environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the exposure recurs through input-handling and injection weakness classes including path traversal, cross-site scripting, OS command injection, and SQL injection, reflecting the product's parser-intensive and command-execution surface. Defenders should prioritize patching this vendor's releases and restrict access to testing and deployment environments where Sahi Pro is deployed; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sahipro over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20470HIGH An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outsi | Jun 17, 2019 | 7.5 | 68 | NO | YES |
CVE-2018-20469CRITICAL An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queri | Jun 17, 2019 | 9.8 | 52 | NO | YES |
CVE-2019-13063HIGH Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the script parameter on the Script_view page. This will result in | Sep 23, 2019 | 7.5 | 49 | NO | YES |
CVE-2019-13597CRITICAL _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts via Sahi Launcher. Also, one can create a new script with an e | Jul 14, 2019 | 9.8 | 48 | NO | YES |
CVE-2019-15102CRITICAL An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attack | Sep 6, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-20472MEDIUM An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS. | Jun 17, 2019 | 5.4 | 29 | NO | YES |
CVE-2018-20468HIGH An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A web reports module has "export to excel features" that are vulnerable to CSV injection. An attacker can embed Ex | Jun 17, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-13066MEDIUM Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable to reflected XSS, by updating a script's Script Name, Suite | Oct 29, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sahipro.
Media articles that mention a CVE ID that affects a product developed by Sahipro — matched by CVE ID, not by vendor name.