VulnerabilityModified
CVE-2019-19660
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1.
MEDIUM 6.5EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- maxum/rumpus
- Source
- cve@mitre.org
References
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.mdThird Party Advisory
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.mdThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.