ZeroHour

CVE-2019-19685

PoC
CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
Description

RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and deletions.

Vendors
nopcommerce
Products
nopcommerce
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.