First published: Thu Apr 09 2020(Updated: )
Information Exposure vulnerability in eXtplorer makes the /usr/ and /etc/extplorer/ system directories world-accessible over HTTP. Introduced in the Makefile patch file debian/patches/debian-changes-2.1.0b6+dfsg-1 or debian/patches/adds-a-makefile.patch, this can lead to data leakage, information disclosure and potentially remote code execution on the web server. This issue affects all versions of eXtplorer in Ubuntu and Debian
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Joomla Explorer | <=2.1.0 | |
Ubuntu | ||
Debian |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7305 has a medium severity level due to the potential for information exposure.
To fix CVE-2019-7305, ensure that the system directories /usr/ and /etc/extplorer/ are properly restricted to prevent world access.
CVE-2019-7305 primarily affects eXtplorer versions up to and including 2.1.0.
Exploitation of CVE-2019-7305 can lead to unauthorized access to sensitive system directories, resulting in data leakage.
Yes, applying the latest updates of eXtplorer will include fixes for CVE-2019-7305.