---
title: "CVE-2019-25097\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-25097?format=md
keywords: index, follow
---

# CVE-2019-25097

Publication date 5 January 2023

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-25097?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified
as critical. Affected by this issue is some unknown functionality of the
component Directory Content Handler. The manipulation leads to path
traversal. Upgrading to version 2.1.13 is able to address this issue. The
name of the patch is b8fcb888f4ff5e171c16797a4b075c6c6f50bf46. It is
recommended to upgrade the affected component. The identifier of this
vulnerability is VDB-217436.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-25097?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| extplorer | 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-25097?format=md#patch-details)

## Notes

---

### [eslerm](https://launchpad.net/~eslerm)

CVE possibly assigned based on 3 year old commit message
same patch as CVE-2019-25096 and CVE-2019-25098

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| extplorer | * Upstream:   [b8fcb88](https://github.com/soerennb/extplorer/commit/b8fcb888f4ff5e171c16797a4b075c6c6f50bf46) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Adjacent |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25097)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-25097)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-25097)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-25097)

### Other references

* <https://github.com/soerennb/extplorer/releases/tag/v2.1.13>
* <https://www.cve.org/CVERecord?id=CVE-2019-25097>
