A AegiFlow
CRITICALCVSS 9.8EPSS 4.2%

CVE-2019-19634

class.upload.php in verot.net omits .pht from the set of dangerous file extensions

Published
2020-02-28
Modified
2026-07-21
EPSS percentile
90%
Aliases
GHSA-2gc7-w4hw-rr2m
Sources
github-advisory

Summary

class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistverot/class.upload.php

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.