### [CVE-2018-20470](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20470) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files. ### POC #### Reference - http://packetstormsecurity.com/files/153330/Sahi-Pro-7.x-8.x-Directory-Traversal.html - http://packetstormsecurity.com/files/153330/Sahi-Pro-7.x-8.x-Directory-Traversal.html - https://barriersec.com/2019/06/cve-2018-20470-sahi-pro/ - https://barriersec.com/2019/06/cve-2018-20470-sahi-pro/ #### Github - https://github.com/ARPSyndicate/kenzer-templates