CVE-2017-7442: Gonitro Nitro Pro

High severity, CVSS 8.8. EPSS: 40.7% chance of exploitation in the next 30 days.

Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

Affected products

  • Gonitro Nitro Pro: version 11.0.3.173 only

Published 2017-08-03. Last modified 2026-06-17.