ZeroHour

CVE-2019-19634

PoC
CVSS 3.1
9.8 critical
EPSS
4%p90
Published
()
Modified
Description

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

Vendors
verot projectjoomlaworks
Products
verot, k2
Ecosystems
Joomla
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.