{"api_version":"1","generated_at":"2026-07-23T08:58:35+00:00","cve":"CVE-2019-19989","urls":{"html":"https://cve.report/CVE-2019-19989","api":"https://cve.report/api/cve/CVE-2019-19989.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-19989","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-19989"},"summary":{"title":"CVE-2019-19989","description":"An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-02-26 16:15:00","updated_at":"2020-02-27 13:59:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://www.seling.it/","name":"https://www.seling.it/","refsource":"MISC","tags":["Product"],"title":"Controllo accessi, rilevazione presenze e Building Security - Selesta Ingegneria","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.seling.it/product/vam/","name":"https://www.seling.it/product/vam/","refsource":"MISC","tags":["Product","Vendor Advisory"],"title":"Applicativo Controllo Accessi: VAM - Selesta Ingegneria","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html","name":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Gruppo TIM | Vulnerability Research & Advisor","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-19989","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19989","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"19989","vulnerable":"1","versionEndIncluding":"4.29.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"seling","cpe5":"visual_access_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-19989","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html","url":"https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html"},{"url":"https://www.seling.it/","refsource":"MISC","name":"https://www.seling.it/"},{"url":"https://www.seling.it/product/vam/","refsource":"MISC","name":"https://www.seling.it/product/vam/"}]}},"nvd":{"publishedDate":"2020-02-26 16:15:00","lastModifiedDate":"2020-02-27 13:59:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:seling:visual_access_manager:*:*:*:*:*:*:*:*","versionStartIncluding":"4.15.0","versionEndIncluding":"4.29.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"19989","Ordinal":"163815","Title":"CVE-2019-19989","CVE":"CVE-2019-19989","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"19989","Ordinal":"1","NoteData":"An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"19989","Ordinal":"2","NoteData":"2020-02-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"19989","Ordinal":"3","NoteData":"2020-02-26","Type":"Other","Title":"Modified"}]}}}