CVE-2019-19634
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla!
CRITICAL
k2
Package
Description
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
Sévérité
9.8
Critique · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Score retenu : NVD
| Source | Sévérité d'origine | CVSS |
|---|---|---|
| NVD | CRITICAL | 9.8 (v3.1) |
Produit et versions
- Produit
- k2
- Type
- Package
- Corrigée dans
- 1.0.3, 2.0.4
- Publiée
- 17/12/2019
- Modifiée
- 26/06/2026
- CWE
- CWE-434
Versions concernées
- verot — jusqu'à 1.0.3 (exclue)
- verot — 2.0.0 – 2.0.4 (exclue)
- k2 — jusqu'à 2.10.1
Sources
- NVD CVE-2019-19634 vu
Ces informations proviennent des sources ci-dessus ; CVE Oyer n'y ajoute aucune interprétation.
Historique
- Détectée via nvd26/09/2026 09:34 UTC