CVE-2019-16384: Cybelesoft Thinfinity Virtualui
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.
Affected products
- Cybelesoft Thinfinity Virtualui: up to and including 2.5.17.2
Published 2020-06-04. Last modified 2026-06-17.