PT-2019-15089 · Clipsoft · Clipsoft Rexpert

Publicado

2019-10-30

·

Atualizado

2021-11-03

·

CVE-2019-17326

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ClipSoft REXPERT versions 1.0.0.527 and earlier
Description The issue allows a remote attacker to delete arbitrary files by issuing an HTTP GET request with a specially crafted parameter. This requires user interaction, where the target must visit a malicious web page.
Recommendations For ClipSoft REXPERT versions 1.0.0.527 and earlier, consider restricting access to the affected parameter until a fix is available. As a temporary workaround, avoid using the vulnerable parameter in HTTP GET requests to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17326

Produtos afetados

Clipsoft Rexpert