vendor:
ES File Explorer
by:
Nehal Zaman
8.1
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: ES File Explorer
Affected Version From: ES File Explorer v4.1.9.7.4
Affected Version To: ES File Explorer v4.1.9.7.4 (latest version)
Patch Exists: YES
Related CWE: CVE-2019-6447
CPE: a:estrongs:es_file_explorer:4.1.9.7.4
Platforms Tested: Android
2021
ES File Explorer 4.1.9.7.4 – Arbitrary File Read
This exploit allows an attacker to read arbitrary files on a target system using the ES File Explorer app. The vulnerability is identified by CVE-2019-6447. By sending a specially crafted request to the app, an attacker can bypass file access restrictions and read files that they should not have access to. This can lead to unauthorized disclosure of sensitive information.
Mitigation:
The vendor has released a patch for this vulnerability. Users are advised to update to the latest version of ES File Explorer (v4.1.9.7.4) or higher to mitigate the risk. Additionally, it is recommended to avoid opening files from untrusted sources.