CVE-2019-7669: Primasystems Flexair
High severity, CVSS 8.8. EPSS: 31.4% chance of exploitation in the next 30 days.
Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allow a remote authenticated attacker to upload and execute malicious applications within the application’s web root with root privileges.
Affected products
- Primasystems Flexair: up to and including 2.3.38
Published 2019-07-01. Last modified 2026-06-17.