CVE-2019-14671

LOW

Firefly III 4.7.17.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.

References (2)

Core 2

Scores

CVSS v3 3.3
EPSS 0.0005
EPSS Percentile 16.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-20
Status published
Products (2)
firefly-iii/firefly_iii 4.7.17.3
grumpydictator/firefly-iii 0 - 4.7.17.4Packagist
Published Aug 05, 2019
Tracked Since Feb 18, 2026