{"id":"GHSA-r5gm-4p5w-pq2p","summary":"Remote code execution in verot/class.upload.php","details":"class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.","aliases":["CVE-2019-19576"],"modified":"2026-07-21T15:15:50.925946484Z","published":"2020-01-16T22:17:40Z","database_specific":{"nvd_published_at":"2019-12-04T18:15:16Z","cwe_ids":["CWE-434"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2020-01-16T22:17:24Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19576"},{"type":"WEB","url":"https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124"},{"type":"WEB","url":"https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1"},{"type":"WEB","url":"https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2"},{"type":"WEB","url":"https://github.com/jra89/CVE-2019-19576"},{"type":"WEB","url":"https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3"},{"type":"WEB","url":"https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4"},{"type":"WEB","url":"https://medium.com/%40jra8908/cve-2019-19576-e9da712b779"},{"type":"WEB","url":"https://medium.com/@jra8908/cve-2019-19576-e9da712b779"},{"type":"WEB","url":"https://www.verot.net"},{"type":"WEB","url":"https://www.verot.net/php_class_upload.htm"},{"type":"WEB","url":"http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html"}],"affected":[{"package":{"name":"verot/class.upload.php","ecosystem":"Packagist","purl":"pkg:composer/verot/class.upload.php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.3"}]}],"versions":["1.0.0","1.0.1","1.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-r5gm-4p5w-pq2p/GHSA-r5gm-4p5w-pq2p.json"}},{"package":{"name":"verot/class.upload.php","ecosystem":"Packagist","purl":"pkg:composer/verot/class.upload.php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.4"}]}],"versions":["2.0.0","2.0.1","2.0.2","2.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/01/GHSA-r5gm-4p5w-pq2p/GHSA-r5gm-4p5w-pq2p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}