MEDIUM · 4.2

CVE-2019-8345

The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an ...

Vulnerability Description

The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.

CVSS Score

4.2

MEDIUM

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
EstrongsEs File Explorer File Manager4.1.9.7.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-8345?

CVE-2019-8345 is a vulnerability with a CVSS score of 4.2 (MEDIUM). The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an ...

How severe is CVE-2019-8345?

CVE-2019-8345 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-8345?

Check the references section above for vendor advisories and patch information. Affected products include: Estrongs Es File Explorer File Manager.