Skip to main content
HIGH

CVE-2019-19731

CVSS v3

7.5

HIGH

EPSS Score

11.6 %

exploit probability, as of 2026-10-04

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

Technical details

Published
2019-12-16
Exploit-DB
EDB-47777

Frequently asked questions

What is CVE-2019-19731?

Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary locations via the RENAMEFILE action. This can be leveraged for code execution by uploading a specially crafted Windows shortcut file and writing the file to the Startup folder (because an incomplete blacklist of file extensions allows Windows shortcut files to be uploaded).

Is CVE-2019-19731 actively exploited?

Active exploitation of CVE-2019-19731 has not been confirmed. Its EPSS score was 11.6% on 2026-10-04, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-19731?

CVE-2019-19731 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-19731 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key