PT-2019-18978 · Es Global · Es File Explorer File Manager
Published
2019-02-15
·
Updated
2021-07-21
·
CVE-2019-8345
CVSS v2.0
4.3
Medium
| Vector | AV:A/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
ES File Explorer File Manager application version 4.1.9.7.4
Description
The issue allows session hijacking by a Man-in-the-middle attacker on the local network. This is because the application does not use HTTPS, and an attacker's website is displayed in a WebView with no information about the URL.
Recommendations
For version 4.1.9.7.4, consider disabling the Help feature that uses a WebView until a patch is available to mitigate the risk of session hijacking. Restrict access to untrusted networks to minimize the risk of exploitation by a Man-in-the-middle attacker.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Es File Explorer File Manager