ZeroHour

CVE-2019-19502

CVSS 3.1
9.8 critical
EPSS
2%p79
Published
()
Modified
Description

Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.

Vendors
maleck
Products
image uploader and browser for ckeditor
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.