CVE-2019-19731: Path Traversal
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2019-19731?
CVE-2019-19731 is a path traversal vulnerability in Roxy Fileman 1.4.5 for .NET that allows remote attackers to write files to arbitrary locations.
What is the severity of CVE-2019-19731?
The severity of CVE-2019-19731 is considered high due to its potential for code execution through the uploading of harmful files.
How do I fix CVE-2019-19731?
To fix CVE-2019-19731, update Roxy Fileman to the latest version that addresses the path traversal vulnerability.
Who is affected by CVE-2019-19731?
CVE-2019-19731 affects users utilizing Roxy Fileman version 1.4.5 for .NET.
What can attackers achieve with CVE-2019-19731?
Attackers can exploit CVE-2019-19731 to upload malicious files, potentially enabling code execution on the server.