SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19020

In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overwriting existing files or adding new PHP files under the web root.

HIGH 7.2EPSS 2.33%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overwriting existing files or adding new PHP files under the web root. This requires the attacker to have access to a valid web interface account.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.33% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-434
Affected
titanhq/webtitan
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.