CVE-2026-41459

Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value rendered in the HTML response, which enables exploitation of path-dependent vulnerabilities such as relative path traversal in connector.php.
Configurations

No configuration.

History

24 Apr 2026, 20:16

Type Values Removed Values Added
References
  • () https://github.com/bootstrapbool/xerteonlinetoolkits-rceĀ -

22 Apr 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-22 19:17

Updated : 2026-04-24 20:16


NVD link : CVE-2026-41459

Mitre link : CVE-2026-41459

CVE.ORG link : CVE-2026-41459


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere