ZeroHour

CVE-2019-14671

PoC
CVSS 3.0
3.3 low
EPSS
<1%p39
Published
()
Modified
Description

Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.

Vendors
firefly-iii
Products
firefly iii
Weakness
CWE-20
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.