Vulnerability Description
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cabsoftware | Reportexpress Proplus | < 3.0.0.62 |
| Microsoft | Windows 10 | - |
| Microsoft | Windows 7 | - |
| Microsoft | Windows 8 | - |
Related Weaknesses (CWE)
References
- http://www.cabsoftware.com:8080/HomePage2015A/html/Vendor Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35474Third Party Advisory
- http://www.cabsoftware.com:8080/HomePage2015A/html/Vendor Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35474Third Party Advisory
FAQ
What is CVE-2019-19160?
CVE-2019-19160 is a vulnerability with a CVSS score of 5.7 (MEDIUM). Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
How severe is CVE-2019-19160?
CVE-2019-19160 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19160?
Check the references section above for vendor advisories and patch information. Affected products include: Cabsoftware Reportexpress Proplus, Microsoft Windows 10, Microsoft Windows 7, Microsoft Windows 8.