### [CVE-2019-12905](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12905) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01. ### POC #### Reference - http://packetstormsecurity.com/files/158173/FileRun-2019.05.21-Cross-Site-Scripting.html - https://github.com/EmreOvunc/FileRun-Vulnerabilities/ - https://github.com/EmreOvunc/FileRun-Vulnerabilities/issues/3 #### Github - https://github.com/EmreOvunc/FileRun-Vulnerabilities