peter bassill · operator
$ cve CVE-2019-18643 JSON

CVE-2019-18643

9.8
CRITICAL · CVSS 3.1 · EPSS 4.3% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklist that can be bypassed by adding multiple spaces and periods after the file name. This could allow an attacker to upload ASPX code and gain remote code execution on the application. The application typically runs as LocalSystem as mandated in the installation guide. Patched in versions 8.10 and 9.4.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.28% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2021-01-07
Last modified2026-06-17

Affected (1)

VendorProduct
sparkdevnetworkrock rms

References

→ the Explorer  ·  watch your stack  ·  NVD