File Path Manipulation Vulnerability in HPE LoadRunner and Performance Center
CVE-2016-4360
9.1CRITICAL
What is CVE-2016-4360?
A vulnerability in the web/admin/data.js file of the Performance Center Virtual Table Server (VTS) component allows remote attackers to exploit unrestricted file paths sent to an unlink call. By manipulating the path parameter in a data/import_csv request, an attacker could potentially delete arbitrary files on the server, posing a significant security risk to data integrity and system stability.