CVE-2019-19576
Remote code execution in verot/class.upload.php
9.8
CRITICAL
CVSS 3.1
EPSS 26.2%
Description
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
How to fix CVE-2019-19576
To remediate CVE-2019-19576, upgrade the affected package to a fixed version below.
- Packagist/verot/class.upload.php—upgrade to 1.0.3 or later
Is CVE-2019-19576 being exploited?
Moderate — EPSS is 26.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.0.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |