Syncpilot Live Contract Path Traversal Vulnerability Allowing Arbitrary File Download

Vulnerability

A path traversal vulnerability has been identified in the file download functionality of Syncpilot Live Contract. This vulnerability allows unauthenticated users to download arbitrary files from the Linux server, within the context of the application server.

Impact

Exploitation of this vulnerability could lead to local file inclusion, allowing attackers to access sensitive files on the server.

Remediation

Users can upgrade to Syncpilot Live Contract versions 5.4.12, 5.5.4, or 5.6.3 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.