Vulnerability Description
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Verot Project | Verot | < 1.0.3 |
| Getk2 | K2 | <= 2.10.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.htExploitThird Party AdvisoryVDB Entry
- https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124PatchThird Party Advisory
- https://github.com/jra89/CVE-2019-19576ExploitThird Party Advisory
- https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae508986PatchThird Party Advisory
- https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7PatchThird Party Advisory
- https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3PatchThird Party Advisory
- https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4PatchThird Party Advisory
- https://medium.com/%40jra8908/cve-2019-19576-e9da712b779
- https://www.verot.netProduct
- https://www.verot.net/php_class_upload.htmVendor Advisory
- http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.htExploitThird Party AdvisoryVDB Entry
- https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124PatchThird Party Advisory
- https://github.com/jra89/CVE-2019-19576ExploitThird Party Advisory
- https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae508986PatchThird Party Advisory
- https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7PatchThird Party Advisory
FAQ
What is CVE-2019-19576?
CVE-2019-19576 is a vulnerability with a CVSS score of 9.8 (CRITICAL). class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
How severe is CVE-2019-19576?
CVE-2019-19576 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19576?
Check the references section above for vendor advisories and patch information. Affected products include: Verot Project Verot, Getk2 K2.