{"id":"CVE-2019-19576","aliases":["GHSA-r5gm-4p5w-pq2p"],"url":"https://o3.security/vulnerability/CVE-2019-19576","summary":"Remote code execution in verot/class.upload.php","details":"class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.","published":"2019-12-04T18:15:16.353Z","modified":"2026-07-08T05:55:22.455411108Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"verot/class.upload.php","fixedVersion":"1.0.3"},{"ecosystem":"Packagist","name":"verot/class.upload.php","fixedVersion":"2.0.4"}],"fix":{"url":"https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124","label":"getk2/k2@d134470"},"references":[{"type":"WEB","url":"https://medium.com/%40jra8908/cve-2019-19576-e9da712b779"},{"type":"WEB","url":"https://www.verot.net"},{"type":"ADVISORY","url":"https://www.verot.net/php_class_upload.htm"},{"type":"FIX","url":"https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124"},{"type":"FIX","url":"https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1"},{"type":"FIX","url":"https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2"},{"type":"FIX","url":"https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3"},{"type":"FIX","url":"https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html"},{"type":"EVIDENCE","url":"https://github.com/jra89/CVE-2019-19576"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:55:22.455411108Z"}}