{"api_version":"1","generated_at":"2026-07-23T11:11:53+00:00","cve":"CVE-2019-19660","urls":{"html":"https://cve.report/CVE-2019-19660","api":"https://cve.report/api/cve/CVE-2019-19660.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-19660","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-19660"},"summary":{"title":"CVE-2019-19660","description":"A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-02-10 16:15:00","updated_at":"2020-02-11 15:12:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.md","name":"https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.md","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/harshit-shukla/CVE","name":"https://github.com/harshit-shukla/CVE","refsource":"MISC","tags":["Third Party Advisory"],"title":"GitHub - harshit-shukla/CVE: CVE's for Rumpus FTP Server","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-19660","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19660","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"19660","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxum","cpe5":"rumpus","cpe6":"8.2.9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"19660","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"maxum","cpe5":"rumpus","cpe6":"8.2.9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-19660","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://github.com/harshit-shukla/CVE","url":"https://github.com/harshit-shukla/CVE"},{"refsource":"MISC","name":"https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.md","url":"https://raw.githubusercontent.com/harshit-shukla/CVE/master/CVE-2019-19660.md"}]}},"nvd":{"publishedDate":"2020-02-10 16:15:00","lastModifiedDate":"2020-02-11 15:12:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:maxum:rumpus:8.2.9.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"19660","Ordinal":"162033","Title":"CVE-2019-19660","CVE":"CVE-2019-19660","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"19660","Ordinal":"1","NoteData":"A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can manipulate the SMTP setting and other network settings via RAPR/NetworkSettingsSet.html.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"19660","Ordinal":"2","NoteData":"2020-02-10","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"19660","Ordinal":"3","NoteData":"2020-02-10","Type":"Other","Title":"Modified"}]}}}