Vulnerability Details CVE-2020-11431
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.6%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2020-11431
-
cpe:2.3:a:inetsoftware:clear_reports:16.0
-
cpe:2.3:a:inetsoftware:clear_reports:16.1
-
cpe:2.3:a:inetsoftware:clear_reports:16.2
-
cpe:2.3:a:inetsoftware:clear_reports:16.3
-
cpe:2.3:a:inetsoftware:clear_reports:16.4
-
cpe:2.3:a:inetsoftware:clear_reports:17.0
-
cpe:2.3:a:inetsoftware:clear_reports:17.1
-
cpe:2.3:a:inetsoftware:clear_reports:18.0
-
cpe:2.3:a:inetsoftware:clear_reports:18.1
-
cpe:2.3:a:inetsoftware:clear_reports:19.0
-
cpe:2.3:a:inetsoftware:clear_reports:19.1
-
cpe:2.3:a:inetsoftware:clear_reports:19.2
-
cpe:2.3:a:inetsoftware:helpdesk:8.0
-
cpe:2.3:a:inetsoftware:helpdesk:8.1
-
cpe:2.3:a:inetsoftware:helpdesk:8.2
-
cpe:2.3:a:inetsoftware:helpdesk:8.3
-
cpe:2.3:a:inetsoftware:pdfc:4.3
-
cpe:2.3:a:inetsoftware:pdfc:5.1
-
cpe:2.3:a:inetsoftware:pdfc:5.2
-
cpe:2.3:a:inetsoftware:pdfc:6.0
-
cpe:2.3:a:inetsoftware:pdfc:6.1
-
cpe:2.3:a:inetsoftware:pdfc:6.2