Lucene search

K
cveMitreCVE-2019-19634
HistoryDec 17, 2019 - 6:15 p.m.

CVE-2019-19634

2019-12-1718:15:14
CWE-434
mitre
web.nvd.nist.gov
61
cve-2019-19634
verot.net
class.upload
joomla
nvd
security
vulnerability
file extension
exploit

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.405

Percentile

97.3%

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

Affected configurations

Nvd
Node
verot_projectverotRange<1.0.3
OR
verot_projectverotRange2.0.02.0.4
Node
getk2k2Range2.10.1joomla\!
VendorProductVersionCPE
verot_projectverot*cpe:2.3:a:verot_project:verot:*:*:*:*:*:*:*:*
getk2k2*cpe:2.3:a:getk2:k2:*:*:*:*:*:joomla\!:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.405

Percentile

97.3%