CVE detail
CVE-2019-15862 — CVE-2019-15862
Published 2019-09-26 · Modified 2026-06-17 · Vendor cksource · Product ckfinder · Source nvd
HIGH
severity
CVSS-derived band
0.0152
EPSS probability
exploitation probability, 30d
72.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References