CVE-2019-14671 describes a local file enumeration vulnerability in Firefly III version 4.7.17.3. This flaw allows an attacker to discover local files on the system due to insufficient sanitization of protocol schemes, specifically file:/// URLs, within the fints_url configuration. The vulnerability has a low CVSS score of 3.3, indicating a low severity. An attacker would require local access and low privileges to exploit this, with the primary impact being the disclosure of local file paths, not their content or modification. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community attention and media coverage, suggesting a low likelihood of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.7.17.3CPE matchmatch criteria | cpe:2.3:a:firefly-iii:firefly_iii:4.7.17.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.