ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation...
Vulnerability Description
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17322
Credits & Attribution
No credits recorded in the NVD database.
More from ClipSoft
View All →Affected Vendor
ClipSoft
View all reports →