PT-2019-18978 · Es Global · Es File Explorer File Manager

Published

2019-02-15

·

Updated

2021-07-21

·

CVE-2019-8345

CVSS v2.0

4.3

Medium

VectorAV:A/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions ES File Explorer File Manager application version 4.1.9.7.4
Description The issue allows session hijacking by a Man-in-the-middle attacker on the local network. This is because the application does not use HTTPS, and an attacker's website is displayed in a WebView with no information about the URL.
Recommendations For version 4.1.9.7.4, consider disabling the Help feature that uses a WebView until a patch is available to mitigate the risk of session hijacking. Restrict access to untrusted networks to minimize the risk of exploitation by a Man-in-the-middle attacker.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-8345

Affected Products

Es File Explorer File Manager