"value":"An issue was discovered in Tyto Sahi Pro 6.x through 8.0.0. TestRunner_Non_distributed (and distributed end points) does not have any authentication mechanism. This allow an attacker to execute an arbitrary script on the remote Sahi Pro server. There is also a password-protected web interface intended for remote access to scripts. This web interface lacks server-side validation, which allows an attacker to create/modify/delete a script remotely without any password. Chaining both of these issues results in remote code execution on the Sahi Pro server."
},
{
"lang":"es",
"value":"Se descubri\u00f3 un problema en Tyto Sahi Pro versiones 6.x hasta 8.0.0. La funci\u00f3n TestRunner_Non_distributed (y end points distribuidos) no posee ning\u00fan mecanismo de autenticaci\u00f3n. Esto permite a un atacante ejecutar un script arbitrario en el servidor remoto Sahi Pro. Tambi\u00e9n presenta una interfaz web protegida por contrase\u00f1a prevista para acceso remoto a los scripts. Esta interfaz web carece de comprobaci\u00f3n del lado del servidor, lo que permite a un atacante crear/modificar/eliminar un script remotamente sin ninguna contrase\u00f1a. Encadenando ambos de los problemas resulta en la ejecuci\u00f3n de c\u00f3digo remota en el servidor Sahi Pro."