← Back

CVE-2019-19634

nvd nist
Published: Dec 17, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

Affected (3)

Products: Verot Project: Verot · Getk2: K2
1 product
Verot
1 product
K2
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Verot Project
Before 1.0.3
From 2.0.0 to 2.0.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.10.1

References (6)

Timeline

No history available yet.