ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-7738 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: krcert
Published:
Updated: 2024-08-05T01:40:14.045Z
Reserved: 2019-10-07T00:00:00
Link: CVE-2019-17325
No data.
Status : Modified
Published: 2019-10-30T21:15:12.130
Modified: 2024-11-21T04:32:05.677
Link: CVE-2019-17325
No data.
OpenCVE Enrichment
No data.
EUVD