PT-2019-18978 · Es Global · Es File Explorer File Manager
Publicado
2019-02-15
·
Atualizado
2021-07-21
·
CVE-2019-8345
CVSS v2.0
4.3
Média
| Vetor | AV:A/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ES File Explorer File Manager application version 4.1.9.7.4
Description
The issue allows session hijacking by a Man-in-the-middle attacker on the local network. This is because the application does not use HTTPS, and an attacker's website is displayed in a WebView with no information about the URL.
Recommendations
For version 4.1.9.7.4, consider disabling the Help feature that uses a WebView until a patch is available to mitigate the risk of session hijacking. Restrict access to untrusted networks to minimize the risk of exploitation by a Man-in-the-middle attacker.
Exploit
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Es File Explorer File Manager