ZeroHour

CVE-2019-8345

PoC
CVSS 3.0
4.2 medium
EPSS
<1%p32
Published
()
Modified
Description

The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.

Vendors
estrongs
Products
es file explorer file manager
Weakness
CWE-319
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.