ZeroHour

CVE-2019-19576

PoC ×2
CVSS 3.1
9.8 critical
EPSS
26%p98
Published
()
Modified
Description

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

Vendors
verot projectjoomlaworks
Products
verot, k2
Ecosystems
Joomla
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.