CVE-2019-10265: Path Traversal
Published Jul 26, 2019
·Updated
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" screen, it is possible to change the directory in the JavaScript code. If changed to (for example) "C:" then one can browse the whole server.
Affected Software
1 affected component
Ahsay Cloud Backup Suite<8.1.1.50
Event History
Jul 26, 2019
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10265?
CVE-2019-10265 has a severity rating of high, with a CVSS score of 7.8.
2
What kind of vulnerability is CVE-2019-10265?
CVE-2019-10265 is a path traversal vulnerability in the Ahsay Cloud Backup Suite.
3
How do I fix CVE-2019-10265?
To fix CVE-2019-10265, upgrade Ahsay Cloud Backup Suite to version 8.1.1.50 or later.
4
What can an attacker do with CVE-2019-10265?
An attacker can exploit CVE-2019-10265 to browse the entire server's file system by manipulating the JavaScript code.
5
In what version of Ahsay Cloud Backup Suite does CVE-2019-10265 exist?
CVE-2019-10265 exists in Ahsay Cloud Backup Suite prior to version 8.1.1.50.