CVE-2019-13984: Malicious File Upload
Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthenticated users, as demonstrated by the EICAR Anti-Virus Test File.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13984?
CVE-2019-13984 is considered a medium severity vulnerability due to its impact on file validation and unauthorized access to uploaded files.
How do I fix CVE-2019-13984?
To fix CVE-2019-13984, upgrade Directus 7 API to version 2.3.0 or later where the file validation issue has been addressed.
What is the impact of CVE-2019-13984?
The impact of CVE-2019-13984 allows unauthenticated users to access and download any uploaded files without proper validation.
Which versions are affected by CVE-2019-13984?
CVE-2019-13984 affects all versions of Directus 7 API prior to 2.3.0.
Can I exploit CVE-2019-13984 without authentication?
Yes, CVE-2019-13984 can be exploited by unauthenticated users, allowing them direct access to uploaded files.