Improper access control in REXPERT - CVE-2019-17322
Published: October 31, 2019
REXPERT
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can create arbitrary files via a POST request with the parameter set to the file path to be written.
Note: To exploit this vulnerability the target must visit a malicious web page.