CVE-2019-19160

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
29/06/2020
Last modified:
07/07/2020

Description

Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into the configure file(rxp).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cabsoftware:reportexpress_proplus:*:*:*:*:*:*:*:* 3.0.0.62 (excluding)
cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_7:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_8:-:*:*:*:*:*:*:*