VYPR
Unrated severityNVD Advisory· Published Aug 25, 2020· Updated May 8, 2025

Cellopoint CelloOS - Unauthenticated Arbitrary File Disclosure

CVE-2020-17385

Description

Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly, which allows unauthorized user to launch Path Traversal attack and access arbitrate file on the system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cellopoint CelloOS v4.1.10 fails to validate URL input, allowing unauthenticated path traversal to read arbitrary system files.

Vulnerability

Cellopoint CelloOS v4.1.10 Build 20190922 does not properly filter special characters in URL parameters, enabling a path traversal attack. The vulnerability resides in the web interface of the email management platform, where user-supplied input is not sanitized for directory traversal sequences such as ../ [1].

Exploitation

An unauthenticated attacker with network access can exploit this by sending a crafted HTTP request containing path traversal sequences in the URL. No authentication or user interaction is required. The attacker can navigate the filesystem by manipulating the ../ patterns to access files outside the intended directory [1].

Impact

Successful exploitation allows the attacker to read arbitrary files on the system, leading to unauthorized disclosure of sensitive information. The CVSS v3.1 score is 7.5 (High) with a confidentiality impact of High and no impact on integrity or availability [1].

Mitigation

The vendor released a fix in CelloOS version 4.1.12 Build 20200701, which was made available via online update on 2020-06-17. Users should update to this version or later to remediate the vulnerability [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Cellopoint/CelloOSllm-create2 versions
    = 4.1.10 Build 20190922+ 1 more
    • (no CPE)range: = 4.1.10 Build 20190922
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.