S4E just found a medium-severity finding from internal ip disclosure vulnerability scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-20470 Scanner

CVE-2018-20470 scanner - Directory Traversal vulnerability in Tyto Sahi Pro

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-20470
7.5
CVSS

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Tyto Sahi Pro is a widely used software testing tool that allows developers to create and execute automated functional and regression tests. With an intuitive graphical user interface, it simplifies the testing process and increases efficiency. Tyto Sahi Pro supports web applications and is available on Windows, Linux, and Mac OS platforms. 

However, there is a significant vulnerability in the Tyto Sahi Pro software discovered in versions 7.x.x and 8.0.0 that can lead to a directory traversal exploit, making it possible for an external attacker to view confidential files. The CVE-2018-20470 vulnerability gets triggered because of an issue in the web reports module, which allows arbitrary file access.

This vulnerability is significant, as it enables an attacker to access files without authorization, including personally identifiable information (PII), sensitive corporate data, and financial information. Once these files are retrieved, an attacker can sell or use them maliciously. 

Through the pro features offered on the s4e.io platform, readers of this article can gain a comprehensive understanding of their digital assets' vulnerabilities in a fast and straightforward manner. With S4E, you can stay informed about the latest cybersecurity threats and employ zero-day protection. Take advantage of the valuable resources available on the platform to stay ahead of the impending threats!

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update Tyto Sahi Pro to the latest version, which resolves the vulnerability.
  • Configure proper file system access control, which can restrict unauthorized access to files.
  • Use web application firewalls with detection and filtering capability.
  • Enforce security policies to ensure that users do not have more privileges than what is required to perform their job functions.
  • Conduct regular security audits to detect vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.