First published: Tue May 14 2019(Updated: )
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rapidflows Rapid4 | =4.5m.23 | |
Microsoft .NET Framework | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11397 is a vulnerability in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) that allows Local File Inclusion via the FileDesc parameter.
CVE-2019-11397 has a severity rating of 6.5 (medium).
RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) is affected by CVE-2019-11397.
To fix CVE-2019-11397, update RapidFlows Enterprise Application Builder to a version that has patched the vulnerability.
You can find more information about CVE-2019-11397 on the RapidFlows website and in the Medium article provided.