CVE-2019-19160
29.06.2020, 14:15
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).Enginsight
Vendor | Product | Version |
---|---|---|
cabsoftware | reportexpress_proplus | 𝑥 < 3.0.0.62 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-353 - Missing Support for Integrity CheckThe software uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.
- CWE-345 - Insufficient Verification of Data AuthenticityThe software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.