Directus 7 Api
Vendor:
First CVE: Jul 19, 2019 · Active for 7 years
5
Total CVEs
More Total CVEs than 77% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Directus 7 Api over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 19, 2019
7 years ago
Most Recent CVE
Jul 19, 2019
2,564 days ago
CVE Severity & Scoring
Directus 7 Api5 CVEs
20%
60%
20%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13983CRITICAL Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php. | Jul 19, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-13984HIGH Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a direct link to each uploaded file, accessible by unauthentic | Jul 19, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-13980HIGH In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx. | Jul 19, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-13979HIGH In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execution. | Jul 19, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-13981MEDIUM In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the uploads/_/originals/ directory. This is related to a configurat | Jul 19, 2019 | 5.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Directus 7 Api
Top CWEs
Versions
No cataloged versions.