CVE-2023-27170

Executive Summary

Xpand IT Write-back manager v2.3.1 is vulnerable to a directory traversal flaw via the siteName parameter, allowing attackers to read arbitrary files and potentially execute code. The vulnerability is not currently listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2023-10-26T23:15:09.253 - Last Modified: 2026-09-16T20:17:20.100

Original Description: Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

"The beginning of knowledge is the discovery of something we do not understand."

— Frank Herbert
Source: NVD