Security Advisory

CVE-2019-19683

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-12-09 16:57:13
Last updated 2024-08-05 02:25:12
Assigner mitre
State PUBLISHED

Description

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/ProcessRequest because of Libraries/Nop.Services/Media/RoxyFileman/FileRoxyFilemanService.cs.