{"api_version":"1","generated_at":"2026-07-23T12:58:03+00:00","cve":"CVE-2019-17321","urls":{"html":"https://cve.report/CVE-2019-17321","api":"https://cve.report/api/cve/CVE-2019-17321.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-17321","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-17321"},"summary":{"title":"CVE-2019-17321","description":"ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required.","state":"PUBLIC","assigner":"vuln@krcert.or.kr","published_at":"2019-10-30 21:15:00","updated_at":"2019-11-01 19:45:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35184","name":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35184","refsource":"MISC","tags":["Third Party Advisory"],"title":"KrCERT/CC - KISA 인터넷 보호나라&KrCERT","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-17321","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17321","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"17321","vulnerable":"1","versionEndIncluding":"1.0.0.527","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"clipsoft","cpe5":"rexpert","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"vuln@krcert.or.kr","ID":"CVE-2019-17321","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"REXPERT","version":{"version_data":[{"version_value":"1.0.0.527 and earlier"}]}}]},"vendor_name":"ClipSoft"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200: Information Exposure"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35184","name":"https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35184"}]}},"nvd":{"publishedDate":"2019-10-30 21:15:00","lastModifiedDate":"2019-11-01 19:45:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:clipsoft:rexpert:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.0.527","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"17321","Ordinal":"157100","Title":"CVE-2019-17321","CVE":"CVE-2019-17321","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"17321","Ordinal":"1","NoteData":"ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"17321","Ordinal":"2","NoteData":"2019-10-30","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"17321","Ordinal":"3","NoteData":"2019-10-30","Type":"Other","Title":"Modified"}]}}}