CVE-2019-19660
Last modified
CVE-2019-19660 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.. EPSS estimates a 0.43% chance of exploitation in the next 30 days.
Description
A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Maxum | Rumpus | 8.2.9.1 |
References
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.mdThird Party Advisory
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19660?
How severe is CVE-2019-19660?
How do I fix CVE-2019-19660?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19648In the macho_parse_file functionality in macho/macho.c of YA…7.8
- CVE-2019-19649Zoho ManageEngine Applications Manager before 13620 allows a…9.8
- CVE-2019-1965A vulnerability in the Virtual Shell (VSH) session managemen…7.7
- CVE-2019-19650Zoho ManageEngine Applications Manager before 13640 allows a…8.8
- CVE-2019-19659A CSRF vulnerability exists in the Web File Manager's Edit A…8.8
- CVE-2019-1966A vulnerability in a specific CLI command within the local m…7.8
- CVE-2019-19661A Cookie based reflected XSS exists in the Web File Manager …6.1
- CVE-2019-19662A CSRF vulnerability exists in the Web File Manager's Create…6.5
- CVE-2019-19663A CSRF vulnerability exists in the Folder Sets Settings of W…6.5
- CVE-2019-19664A CSRF vulnerability exists in the Web Settings of Web File …7.1
- CVE-2019-19665A CSRF vulnerability exists in the FTP Settings of Web File …6.5
- CVE-2019-19666A CSRF vulnerability exists in the Event Notices Settings of…4.3
Are you affected by CVE-2019-19660?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
