{"id":"CVE-2019-14671","aliases":["GHSA-jjcx-999m-35hc"],"url":"https://o3.security/vulnerability/CVE-2019-14671","summary":"Improper Input Validation in Firefly III","details":"Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints.","published":"2019-08-05T20:15:12.203Z","modified":"2026-07-08T20:15:06.587421Z","cvss":{"score":3.3,"severity":"LOW","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"grumpydictator/firefly-iii","fixedVersion":"4.7.17.4"}],"fix":{"url":"https://github.com/firefly-iii/firefly-iii/commit/e80d616ef4397e6e764f6b7b7a5b30121244933c","label":"firefly-iii/firefly-iii@e80d616"},"references":[{"type":"FIX","url":"https://github.com/firefly-iii/firefly-iii/commit/e80d616ef4397e6e764f6b7b7a5b30121244933c"},{"type":"EVIDENCE","url":"https://github.com/firefly-iii/firefly-iii/issues/2367"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:15:06.587421Z"}}