CVE-2019-17199 is a directory traversal vulnerability in WPO WebPageTest 19.04 on Windows, allowing attackers to read arbitrary files due to an unanchored regular expression in www/getfile.php. This vulnerability has a CVSS score of 7.5 (High), indicating a critical risk with network-based exploitation and no user interaction required, leading to high confidentiality impact. While not currently on CISA's KEV catalog, a Metasploit module exists for this vulnerability, suggesting readily available exploit code. Despite its high FAUCET risk score and EPSS percentile, there is minimal community discussion or media coverage, which is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
19.04CPE matchmatch criteria | cpe:2.3:a:webpagetest:webpagetest:19.04:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.