Unrated severityNVD Advisory· Published Apr 30, 2021· Updated Aug 4, 2024
Directory Traversal Vulnerability in SUSI.AI Server
CVE-2020-4039
Description
SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files can also be moved or deleted.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2< d27ed0f+ 1 more
- (no CPE)range: < d27ed0f
- (no CPE)range: <=d27ed0f
Patches
Vulnerability mechanics
References
1- github.com/fossasia/susi_server/security/advisories/GHSA-wcm4-2jp5-q269mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.