PoC Index

CVE-2019-19731

HIGH 7.5EPSS 11.6%

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
11.62% chance of exploitation in the next 30 days, 96th percentile
Published
2019-12-16
Updated
2024-08-05

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related