๐Ÿ” CVE Alert

CVE-2026-41459

MEDIUM 5.3

Xerte Online Toolkits Path Disclosure via /setup

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the application root. Attackers can send a GET request to the /setup page to access the exposed root_path value rendered in the HTML response, which enables exploitation of path-dependent vulnerabilities such as relative path traversal in connector.php.

CWE CWE-497
Vendor thexerteproject
Product xerteonlinetoolkits
Published Apr 22, 2026
Last Updated Apr 22, 2026
Stay Ahead of the Next One

Get instant alerts for thexerteproject xerteonlinetoolkits

Be the first to know when new medium vulnerabilities affecting thexerteproject xerteonlinetoolkits are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

thexerteproject / xerteonlinetoolkits
3.15.0 0 < f063e942b4a9bf77a06829e844c2c70316bc45e8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
xerte.org.uk: https://xerte.org.uk/xertetoolkits_3.15_ChangeLog.html xerte.org.uk: https://xerte.org.uk/index.php/en/downloads-1/category/3-xerte-online-toolkits github.com: https://github.com/thexerteproject/xerteonlinetoolkits/issues/1527 github.com: https://github.com/thexerteproject/xerteonlinetoolkits/commit/f063e942b4a9bf77a06829e844c2c70316bc45e8 vulncheck.com: https://www.vulncheck.com/advisories/xerte-online-toolkits-path-disclosure-via-setup

Credits

bootstrapbool