SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app can be retrieved by the attacker. Furthermore, some files can also be moved or deleted.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T07:52:20.803Z
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4039

No data.

Status : Modified
Published: 2021-04-30T16:15:07.497
Modified: 2024-11-21T05:32:12.123
Link: CVE-2020-4039

No data.