CVE-2020-11431

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
07/05/2020
Last modified:
12/05/2020

Description

The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inetsoftware:clear_reports:*:*:*:*:*:*:*:* 16.0 (including) 19.2 (including)
cpe:2.3:a:inetsoftware:helpdesk:*:*:*:*:*:*:*:* 8.0 (including) 8.3 (including)
cpe:2.3:a:inetsoftware:pdfc:*:*:*:*:*:*:*:* 4.3 (including) 6.2 (including)