// For flags

CVE-2019-14251

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

Se detectó un problema en T24 en TEMENOS Channels versión R15.01. La página de inicio de sesión presenta funciones de JavaScript para acceder a un documento en el servidor una vez autenticado con éxito. Sin embargo, un atacante puede aprovechar la función downloadDocServer() para saltar el sistema de archivos y acceder a archivos o directorios que se encuentran fuera del directorio restringido porque WealthT24/GetImage es usado con los parámetros docDownloadPath y uploadLocation.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-07-24 CVE Reserved
  • 2019-12-09 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • 2024-10-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Temenos
Search vendor "Temenos"
T24
Search vendor "Temenos" for product "T24"
r15.01
Search vendor "Temenos" for product "T24" and version "r15.01"
-
Affected