CVE-2019-19634

Vulnérabilités

CVE-2019-19634

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!

CRITICAL k2 Package

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

9.8 Critique · CVSS 3.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Score retenu : NVD

SourceSévérité d'origineCVSS
NVDCRITICAL 9.8 (v3.1)
Produit
k2
Type
Package
Corrigée dans
1.0.3, 2.0.4
Publiée
17/12/2019
Modifiée
26/06/2026
CWE
CWE-434
  • verot — jusqu'à 1.0.3 (exclue)
  • verot — 2.0.0 – 2.0.4 (exclue)
  • k2 — jusqu'à 2.10.1

Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.

  1. Détectée via nvd26/09/2026 09:34 UTC