Syncpilot Live Contract Path Traversal Vulnerability Allowing Arbitrary File Download
Vulnerability
A path traversal vulnerability has been identified in the file download functionality of Syncpilot Live Contract. This vulnerability allows unauthenticated users to download arbitrary files from the Linux server, within the context of the application server.
Impact
Exploitation of this vulnerability could lead to local file inclusion, allowing attackers to access sensitive files on the server.
Remediation
Users can upgrade to Syncpilot Live Contract versions 5.4.12, 5.5.4, or 5.6.3 to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
7.4remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
