A AegiFlow
CRITICALCVSS 9.8EPSS 26.2%

CVE-2019-19576

Remote code execution in verot/class.upload.php

Published
2020-01-16
Modified
2026-07-21
EPSS percentile
98%
Aliases
GHSA-r5gm-4p5w-pq2p
Sources
github-advisory

Summary

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistverot/class.upload.php1.0.3, 2.0.4

Remediation: Upgrade to 1.0.3 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.