PT-2019-15085 · Clipsoft · Clipsoft Rexpert
Published
2019-10-30
·
Updated
2021-11-03
·
CVE-2019-17322
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ClipSoft REXPERT versions 1.0.0.527 and earlier
Description
The issue allows for arbitrary file creation via a POST request with the
parameter set to the file path to be written, potentially allowing the creation of executable files in arbitrary directories. User interaction is required, where the target must visit a malicious web page to exploit this issue.Recommendations
For ClipSoft REXPERT versions 1.0.0.527 and earlier, as a temporary workaround, consider restricting access to the POST request endpoint to minimize the risk of exploitation. Avoid using the
parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clipsoft Rexpert