Cellopoint CelloOS - Unauthenticated Arbitrary File Disclosure
Description
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cellopoint CelloOS v4.1.10 fails to validate URL input, allowing unauthenticated path traversal to read arbitrary system files.
Vulnerability
Cellopoint CelloOS v4.1.10 Build 20190922 does not properly filter special characters in URL parameters, enabling a path traversal attack. The vulnerability resides in the web interface of the email management platform, where user-supplied input is not sanitized for directory traversal sequences such as ../ [1].
Exploitation
An unauthenticated attacker with network access can exploit this by sending a crafted HTTP request containing path traversal sequences in the URL. No authentication or user interaction is required. The attacker can navigate the filesystem by manipulating the ../ patterns to access files outside the intended directory [1].
Impact
Successful exploitation allows the attacker to read arbitrary files on the system, leading to unauthorized disclosure of sensitive information. The CVSS v3.1 score is 7.5 (High) with a confidentiality impact of High and no impact on integrity or availability [1].
Mitigation
The vendor released a fix in CelloOS version 4.1.12 Build 20200701, which was made available via online update on 2020-06-17. Users should update to this version or later to remediate the vulnerability [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2= 4.1.10 Build 20190922+ 1 more
- (no CPE)range: = 4.1.10 Build 20190922
- (no CPE)range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-3846-7790c-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.