#VU22443 Improper access control in REXPERT - CVE-2019-17326
Published: October 31, 2019
REXPERT
ClipSoft
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker can issue a HTTP GET request with a specially crafted parameter, bypass implemented security restrictions and delete files on the target system.
Note: To exploit this vulnerability the target must visit a malicious web page.