CVE-2019-17321

ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clipsoft:rexpert:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:32

Type Values Removed Values Added
References () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35184 - Third Party Advisory () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35184 - Third Party Advisory

Information

Published : 2019-10-30 21:15

Updated : 2024-11-21 04:32


NVD link : CVE-2019-17321

Mitre link : CVE-2019-17321

CVE.ORG link : CVE-2019-17321


JSON object : View

Products Affected

clipsoft

  • rexpert
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor