CyberRota Analysis
AI-GeneratedGFI Exinda AI and ClearView versions prior to 7.6.5 are vulnerable to a path traversal flaw in the system maintenance configuration download handler, allowing an authenticated attacker with Admin privileges to access arbitrary files on the system. This could lead to unauthorized disclosure of sensitive information, as the vulnerability permits reading files in the context of the root directory. Organizations using these products should prioritize patching to mitigate potential data exposure risks.
Original NVD Description
GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for directory traversal sequences. An authenticated attacker with Admin privileges can read arbitrary files from the system in the context of root.