CVE-2019-13464

HIGH

Owasp Modsecurity Core Rule Set - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypass some PHP Script Uploads rules, because PHP automatically transforms dots into underscores in certain contexts where dots are invalid.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1386

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 46.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (1)
modsecurity/owasp_modsecurity_core_rule_set 3.0.2
Published Jul 09, 2019
Tracked Since Feb 18, 2026