CVE-2019-19576

Vulnérabilités

CVE-2019-19576

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!

CRITICAL k2 Package

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

9.8 Critique · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDCRITICAL 9.8 (v3.1)
Produit
k2
Type
Package
Corrigée dans
1.0.3, 2.0.4
Publiée
04/12/2019
Modifiée
26/06/2026
CWE
CWE-434
  • verot — jusqu'à 1.0.3 (exclue)
  • verot — 2.0.0 – 2.0.4 (exclue)
  • k2 — jusqu'à 2.10.1

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC