Back to CVE List

CVE-2026-41459

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Vulnerability Description

Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value rendered in the HTML response, which enables exploitation of path-dependent vulnerabilities such as relative path traversal in connector.php.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-497
Source
NVD
Vendor
thexerteproject
Product
xerteonlinetoolkits

External References

Discussion (0)

Add Comment

No comments yet. Be the first!