CVE-2019-13980: Malicious File Upload
Published Jul 19, 2019
·Updated
In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads//originals remote code execution with nginx.
Affected Software
1 affected component
Rangerstudio Directus 7 Api<=2.3.0
Event History
Jul 19, 2019
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13980?
CVE-2019-13980 is considered to have a high severity due to the potential for remote code execution.
2
How do I fix CVE-2019-13980?
To fix CVE-2019-13980, upgrade to a version of Directus 7 API later than 2.3.0.
3
What does CVE-2019-13980 affect?
CVE-2019-13980 specifically affects versions of Directus 7 API up to and including 2.3.0.
4
What are the implications of exploiting CVE-2019-13980?
Exploiting CVE-2019-13980 can lead to remote code execution on servers using nginx, which may allow attackers to compromise the system.
5
Can CVE-2019-13980 be exploited with any web server?
CVE-2019-13980 can only be exploited with the nginx web server, as vulnerability mitigations apply when using Apache.