CVE-2019-19634: Malicious File Upload
class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! and other products, omits .pht from the set of dangerous file extensions, a similar issue to CVE-2019-19576.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19634?
CVE-2019-19634 is a vulnerability in class.upload.php through version 1.0.3 and 2.x through 2.0.4, which is used in the K2 extension for Joomla! and other products.
What is the severity of CVE-2019-19634?
The severity of CVE-2019-19634 is critical with a CVSS score of 9.8.
How does CVE-2019-19634 affect Verot Project Verot?
CVE-2019-19634 affects Verot Project Verot up to version 1.0.3 and version 2.x up to version 2.0.4.
How does CVE-2019-19634 affect Getk2 K2?
CVE-2019-19634 affects Getk2 K2 up to version 2.10.1.
Where can I find more information about CVE-2019-19634?
More information about CVE-2019-19634 can be found at the following references: [Link 1](https://github.com/jra89/CVE-2019-19634), [Link 2](https://github.com/verot/class.upload.php/blob/2.0.4/src/class.upload.php#L3068), [Link 3](https://medium.com/@jra8908/cve-2019-19634-arbitrary-file-upload-in-class-upload-php-ccaf9e13875e).