First published: Tue Apr 09 2019(Updated: )
Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), fileslist.php (aka Echo File List), and movefile.php (aka Move File) operations.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Brakeman | =1.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7174 is classified as a high severity vulnerability due to its potential to allow unauthorized file operations.
To fix CVE-2019-7174, update Roxy Fileman to the latest version that addresses this vulnerability.
CVE-2019-7174 specifically affects Roxy Fileman version 1.4.5.
CVE-2019-7174 allows attackers to execute file management operations like renaming, creating, and moving files without proper authorization.
A temporary workaround for CVE-2019-7174 is to restrict access to Roxy Fileman or remove it entirely until it can be updated.