SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-7305

Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP.

CRITICAL 9.8EPSS 1.83%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.83% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-552
Affected
extplorer/extplorer
Source
security@ubuntu.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.