Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-8345

Опубликовано: 15 фев. 2019
Источник: nvd
CVSS3: 4.2
CVSS2: 4.3
EPSS Низкий

Описание

The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:estrongs:es_file_explorer_file_manager:4.1.9.7.4:*:*:*:*:android:*:*

EPSS

Процентиль: 10%
0.00035
Низкий

4.2 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 4.2
github
больше 3 лет назад

The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.

EPSS

Процентиль: 10%
0.00035
Низкий

4.2 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-319