Vulnerability Details CVE-2019-16384
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2019-16384
-
cpe:2.3:a:cybelesoft:thinfinity_virtualui:2.0
-
cpe:2.3:a:cybelesoft:thinfinity_virtualui:2.1.28.0
-
cpe:2.3:a:cybelesoft:thinfinity_virtualui:2.1.32.1
-
cpe:2.3:a:cybelesoft:thinfinity_virtualui:2.5
-
cpe:2.3:a:cybelesoft:thinfinity_virtualui:2.5.17.2