CVE-2019-19731: Roxyfileman Roxy Fileman
High severity, CVSS 7.5. EPSS: 11.6% chance of exploitation in the next 30 days.
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).
Affected products
- Roxyfileman Roxy Fileman: version 1.4.5 only
Published 2019-12-16. Last modified 2026-06-17.