VulnerabilityModified
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
CRITICAL 9.8EPSS 26.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 26.38% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- verot project/verot · joomlaworks/k2
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124Patch, Third Party Advisory
- https://github.com/jra89/CVE-2019-19576Exploit, Third Party Advisory
- https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1Patch, Third Party Advisory
- https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2Patch, Third Party Advisory
- https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3Patch, Third Party Advisory
- https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4Patch, Third Party Advisory
- https://medium.com/%40jra8908/cve-2019-19576-e9da712b779
- https://www.verot.netProduct
- https://www.verot.net/php_class_upload.htmVendor Advisory
- http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124Patch, Third Party Advisory
- https://github.com/jra89/CVE-2019-19576Exploit, Third Party Advisory
- https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1Patch, Third Party Advisory
- https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2Patch, Third Party Advisory
- https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3Patch, Third Party Advisory
- https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4Patch, Third Party Advisory
- https://medium.com/%40jra8908/cve-2019-19576-e9da712b779
- https://www.verot.netProduct
- https://www.verot.net/php_class_upload.htmVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.