CVE detail
CVE-2019-13981 — CVE-2019-13981
Published 2019-07-19 · Modified 2026-06-17 · Vendor rangerstudio · Product directus_7_api · Source nvd
MEDIUM
severity
CVSS-derived band
0.0150
EPSS probability
exploitation probability, 30d
72.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configuration option in which the file collection can be non-public, but this option does not apply to the thumbnailer.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References