peter bassill · operator
$ cve CVE-2019-19576 JSON

CVE-2019-19576 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 26.4% (pctl 98)

Patch early

A public exploit exists.

Description

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS26.38% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2019-12-04
Last modified2026-06-26

Affected (2)

VendorProduct
joomlaworksk2
verot projectverot

Public exploits

SourceTitleDate
exploit-dbVerot 2.0.3 - Remote Code Execution2019-12-06

References

→ the Explorer  ·  watch your stack  ·  NVD