PT-2019-15088 · Clipsoft · Rexpert+1

Publicado

2019-10-30

·

Atualizado

2019-11-01

·

CVE-2019-17325

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ClipSoft REXPERT version 1.0.0.527 and earlier
Description The issue allows a remote attacker to upload arbitrary local files via the ActiveX method in RexViewerCtrl30.ocx, potentially leading to the disclosure of sensitive information. This can be exploited when a user visits a malicious web page, requiring user interaction.
Recommendations For ClipSoft REXPERT version 1.0.0.527 and earlier, consider disabling the ActiveX method in RexViewerCtrl30.ocx as a temporary workaround until a patch is available. Restrict access to the RexViewerCtrl30.ocx module to minimize the risk of exploitation.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17325

Produtos afetados

Rexpert
Rexviewerctrl30.Ocx