Executive brief
A security vulnerability has been identified in Vedo Suite 2024.17, a management software platform. An attacker can exploit this flaw to access and read sensitive files stored on the underlying server's filesystem. This could lead to the exposure of configuration data, system credentials, or other private information, potentially compromising the entire server.
Technical details
A relative path traversal vulnerability (CWE-23) exists in Vedo Suite version 2024.17. The flaw is located within the '/api_vedo/template' endpoint, which utilizes the PHP 'file_get_contents()' function without sufficient input validation or sanitization. A remote authenticated attacker can supply specially crafted input containing directory traversal sequences (e.g., ../) to bypass intended directory restrictions. This allows the attacker to read arbitrary files from the server's filesystem that the web server process has permissions to access. While the advisory mentions 'authenticated' in the description, the provided CVSS vector (PR:N) suggests a potential for unauthenticated access; however, the description's mention of authentication should be noted as a likely precondition.
Affected products
- Vedo Suite Project Vedo Suite 2024.17
Timeline
- 2025-08-06: advisory: Initial NVD publication