ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: krcert
Published: 2019-10-30T20:55:11
Updated: 2024-08-05T01:40:14.045Z
Reserved: 2019-10-07T00:00:00
Link: CVE-2019-17325
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-10-30T21:15:12.130
Modified: 2024-11-21T04:32:05.677
Link: CVE-2019-17325
Redhat
No data.