{"id":"CVE-2019-13980","details":"In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to uploads/_/originals remote code execution with nginx.","modified":"2026-08-27T08:15:19.703594Z","published":"2019-07-19T15:15:12.250Z","references":[{"type":"REPORT","url":"https://github.com/directus/api/issues/979"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/directus/v8-archive","events":[{"introduced":"0"},{"last_affected":"ff05f586f4457c57ea3722bfb634b1d2b52b6c38"}],"database_specific":{"cpe":"cpe:2.3:a:rangerstudio:directus_7_api:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.3.0"}],"source":"CPE_RANGE"}}],"versions":["v2.3.0","v2.0.0-beta.1","2.0.0-alpha.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13980.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}