First published: Mon Jun 29 2020(Updated: )
Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).
Credit: vuln@krcert.or.kr
Affected Software | Affected Version | How to fix |
---|---|---|
Cabsoftware Reportexpress Proplus | <3.0.0.62 | |
Microsoft Windows 10 | ||
Microsoft Windows 7 | ||
Microsoft Windows 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19160 is a vulnerability in Reportexpress ProPlus that could allow arbitrary code execution.
Reportexpress ProPlus version up to 3.0.0.62 is affected by CVE-2019-19160.
The severity of CVE-2019-19160 is high, with a CVSS score of 8.8.
CVE-2019-19160 can be exploited by inserting VBscript into the configure file (rxp).
No, Microsoft Windows 10, Windows 7, and Windows 8 are not vulnerable to CVE-2019-19160.