CVE-2020-17385

Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
Configurations

Configuration 1 (hide)

cpe:2.3:o:cellopoint:cellos:4.1.10:build20190922:*:*:*:*:*:*

History

08 May 2025, 10:15

Type Values Removed Values Added
Summary (en) Cellopoint Cellos v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system. (en) Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.

21 Nov 2024, 05:07

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-3846-7790c-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-3846-7790c-1.html - Third Party Advisory

Information

Published : 2020-08-25 08:15

Updated : 2025-05-08 10:15


NVD link : CVE-2020-17385

Mitre link : CVE-2020-17385

CVE.ORG link : CVE-2020-17385


JSON object : View

Products Affected

cellopoint

  • cellos
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')