Path Traversal Vulnerability in Roxy Fileman 1.4.5 for .NET Allows Arbitrary File Write and Code Execution

Path Traversal Vulnerability in Roxy Fileman 1.4.5 for .NET Allows Arbitrary File Write and Code Execution

CVE-2019-19731 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

Learn more about our Web Application Penetration Testing UK.