VulnerabilityModified
CVE-2019-19668
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
MEDIUM 4.3EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- maxum/rumpus ftp
- Source
- cve@mitre.org
References
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://github.com/harshit-shukla/CVE/blob/master/CVE-2019-19668.mdThird Party Advisory
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://github.com/harshit-shukla/CVE/blob/master/CVE-2019-19668.mdThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.