CVE Feed

    Dashboard / CVE / CVE-2019-19576

    CVE-2019-19576

    class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

    Published:Dec 4, 2019
    Last Modified:Nov 21, 2024
    EPS:Dec 4, 2019
    EPSS Score:0.44137
    CVSS Score:9.8

    Affected Products

    Vendor
    Getk2
    Product
    K2
    Vendor
    Verot Project
    Product
    Verot

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High