peter bassill · operator
$ cve CVE-2019-19731 JSON

CVE-2019-19731 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 11.6% (pctl 96)

Patch early

A public exploit exists.

Description

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS11.62% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2019-12-16
Last modified2026-06-17

Affected (1)

VendorProduct
roxyfilemanroxy fileman

Public exploits

SourceTitleDate
exploit-dbRoxy Fileman 1.4.5 - Directory Traversal2019-12-16

References

→ the Explorer  ·  watch your stack  ·  NVD