CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
k2
Package
Description
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
Sévérité
9.8
Critique · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.8 (v3.1) |
Produit et versions
- Produit
- k2
- Type
- Package
- Corrigée dans
- 1.0.3, 2.0.4
- Publiée
- 04/12/2019
- Modifiée
- 26/06/2026
- CWE
- CWE-434
Versions concernées
- verot — jusqu'à 1.0.3 (exclue)
- verot — 2.0.0 – 2.0.4 (exclue)
- k2 — jusqu'à 2.10.1
Sources
- NVD CVE-2019-19576 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC
RéférencesJSON
- packetstormsecurity.comExploit, Third Party Advisory, VDB Entry
- github.comPatch, Third Party Advisory
- github.comExploit, Third Party Advisory
- github.comPatch, Third Party Advisory
- github.comPatch, Third Party Advisory
- github.comPatch, Third Party Advisory
- github.comPatch, Third Party Advisory
- medium.comNVD
- www.verot.netProduct
- www.verot.netVendor Advisory