CRITICAL 9.8
GHSA-r5gm-4p5w-pq2p
Remote code execution in verot/class.upload.php
Quick fix
GHSA-r5gm-4p5w-pq2p — verot/class.upload.php: upgrade to the fixed version with the command below.
composer require verot/class.upload.php:^1.0.3 Details
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist / verot/class.upload.php
Introduced in:
0 Fixed in: 1.0.3 Fix
composer require verot/class.upload.php:^1.0.3 Packagist / verot/class.upload.php
Introduced in:
2.0.0 Fixed in: 2.0.4 Fix
composer require verot/class.upload.php:^2.0.4 References
- https://nvd.nist.gov/vuln/detail/CVE-2019-19576 [ADVISORY]
- https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124 [WEB]
- https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1 [WEB]
- https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2 [WEB]
- https://github.com/jra89/CVE-2019-19576 [WEB]
- https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3 [WEB]
- https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4 [WEB]
- https://medium.com/%40jra8908/cve-2019-19576-e9da712b779 [WEB]
- https://medium.com/@jra8908/cve-2019-19576-e9da712b779 [WEB]
- https://www.verot.net [WEB]
- https://www.verot.net/php_class_upload.htm [WEB]
- http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html [WEB]