CVE-2019-17325

MEDIUM

ClipSoft REXPERT < 1.0.0.527 - Unrestricted File Upload via RexViewerCtrl30.ocx ActiveX Method

Title source: llm
STIX 2.1

Description

ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0125
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-434
Status published
Products (1)
clipsoft/rexpert < 1.0.0.527
Published Oct 30, 2019
Tracked Since Feb 18, 2026