PT-2019-15931 · Kcfinder · Roxy Fileman

Published

2019-12-16

·

Updated

2019-12-23

·

CVE-2019-19731

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Roxy Fileman version 1.4.5
Description The issue allows a remote attacker to perform path traversal, enabling them to write uploaded files to arbitrary locations using the RENAMEFILE action. This can be exploited for code execution by uploading a specially crafted Windows shortcut file and writing it to the Startup folder, as the blacklist of file extensions is incomplete, permitting Windows shortcut files to be uploaded.
Recommendations For version 1.4.5, consider restricting access to the RENAMEFILE action until a patch is available, and ensure that Windows shortcut files are properly blocked from being uploaded to prevent code execution.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19731

Affected Products

Roxy Fileman