Parallels System Automation "locale" Directory Traversal Vulnerability
Description
A vulnerability has been identified in Parallels System Automation, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "/servlet/Help" script when processing the "locale" parameter, which could be exploited to disclose the contents of arbitrary files via directory traversal attacks.
Vulnerable Products
Vulnerable Software: Parallels System Automation (PSA)