CVE-2019-17325

MEDIUM

Clipsoft Rexpert < 1.0.0.527 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0047
EPSS Percentile 64.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-434
Status published
Products (1)
clipsoft/rexpert < 1.0.0.527
Published Oct 30, 2019
Tracked Since Feb 18, 2026