CVE-2019-19668
Last modified
CVE-2019-19668 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Maxum | Rumpus Ftp | 8.2.9.1 |
References
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://github.com/harshit-shukla/CVE/blob/master/CVE-2019-19668.mdThird Party Advisory
- https://github.com/harshit-shukla/CVEThird Party Advisory
- https://github.com/harshit-shukla/CVE/blob/master/CVE-2019-19668.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19668?
How severe is CVE-2019-19668?
How do I fix CVE-2019-19668?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19662A CSRF vulnerability exists in the Web File Manager's Create…6.5
- CVE-2019-19663A CSRF vulnerability exists in the Folder Sets Settings of W…6.5
- CVE-2019-19664A CSRF vulnerability exists in the Web Settings of Web File …7.1
- CVE-2019-19665A CSRF vulnerability exists in the FTP Settings of Web File …6.5
- CVE-2019-19666A CSRF vulnerability exists in the Event Notices Settings of…4.3
- CVE-2019-19667A CSRF vulnerability exists in the Block Clients component o…5.4
- CVE-2019-19669A CSRF vulnerability exists in the Upload Center Forms Compo…6.5
- CVE-2019-1967A vulnerability in the Network Time Protocol (NTP) feature o…7.5
- CVE-2019-19670A HTTP Response Splitting vulnerability was identified in th…6.1
- CVE-2019-19675In Ivanti Workspace Control before 10.3.180.0. a locally aut…7.8
- CVE-2019-19676A CSV injection in arxes-tolina 3.0.0 allows malicious users…9.6
- CVE-2019-19677arxes-tolina 3.0.0 allows User Enumeration.4.3
Are you affected by CVE-2019-19668?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
