Tyto Sahi Pro versions through 7.x.x and 8.0.0 are susceptible to a local file inclusion vulnerability in the web reports module which can allow an outside attacker to view contents of sensitive files.
id: CVE-2018-20470
info:
name: Tyto Sahi pro 7.x/8.x - Local File Inclusion
author: daffainfo
...