Directus 7 Api

Vendor:

First CVE: Jul 19, 2019 · Active for 7 years

5
Total CVEs
More Total CVEs than 77% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Directus 7 Api over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2019
7 years ago
Most Recent CVE
Jul 19, 2019
2,564 days ago

CVE Severity & Scoring

Directus 7 Api5 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.
Jul 19, 20199.830NONO
Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthentic
Jul 19, 20198.827NONO
In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.
Jul 19, 20198.827NONO
In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution.
Jul 19, 20198.826NONO
In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configurat
Jul 19, 20195.319NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Directus 7 Api

Top CWEs

Versions

No cataloged versions.