PT-2019-18978 · Es Global · Es File Explorer File Manager

Publicado

2019-02-15

·

Atualizado

2021-07-21

·

CVE-2019-8345

CVSS v2.0

4.3

Média

VetorAV:A/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions ES File Explorer File Manager application version 4.1.9.7.4
Description The issue allows session hijacking by a Man-in-the-middle attacker on the local network. This is because the application does not use HTTPS, and an attacker's website is displayed in a WebView with no information about the URL.
Recommendations For version 4.1.9.7.4, consider disabling the Help feature that uses a WebView until a patch is available to mitigate the risk of session hijacking. Restrict access to untrusted networks to minimize the risk of exploitation by a Man-in-the-middle attacker.

Exploit

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8345

Produtos afetados

Es File Explorer File Manager