PT-2019-15085 · Clipsoft · Clipsoft Rexpert

Published

2019-10-30

·

Updated

2021-11-03

·

CVE-2019-17322

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ClipSoft REXPERT versions 1.0.0.527 and earlier
Description The issue allows for arbitrary file creation via a POST request with the parameter set to the file path to be written, potentially allowing the creation of executable files in arbitrary directories. User interaction is required, where the target must visit a malicious web page to exploit this issue.
Recommendations For ClipSoft REXPERT versions 1.0.0.527 and earlier, as a temporary workaround, consider restricting access to the POST request endpoint to minimize the risk of exploitation. Avoid using the parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-17322

Affected Products

Clipsoft Rexpert