SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17322

ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written.

MEDIUM 6.5EPSS 1.22%

Does this matter?

Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.

Description

ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
1.22% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-264, CWE-22
Affected
clipsoft/rexpert
Source
vuln@krcert.or.kr

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.