Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value rendered in the HTML response, which enables exploitation of path-dependent vulnerabilities such as relative path traversal in connector.php.
References
Configurations
No configuration.
History
24 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
22 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 19:17
Updated : 2026-04-24 20:16
NVD link : CVE-2026-41459
Mitre link : CVE-2026-41459
CVE.ORG link : CVE-2026-41459
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
