CVE-2018-17287: Kofax Front Office Server
Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end "download" feature, as demonstrated by an mfp.password downloadsettingvalue operation.
Affected products
- Kofax Front Office Server: version 4.1.1.11.0.5212 only
Published 2019-04-18. Last modified 2026-06-17.