{"id":"CVE-2019-19576","title":"class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.","summary":"class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-434"],"vendor":"verot_project","product":"verot","affected":["verot < 1.0.3","verot >= 2.0.0, < 2.0.4","k2 <= 2.10.1"],"patched":["verot 2.0.4"],"published":"2019-12-04","updated":"2026-06-26","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-19576","references":[{"url":"http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html","label":"cve@mitre.org"},{"url":"https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124","label":"cve@mitre.org"},{"url":"https://github.com/jra89/CVE-2019-19576","label":"cve@mitre.org"},{"url":"https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1","label":"cve@mitre.org"},{"url":"https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2","label":"cve@mitre.org"},{"url":"https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3","label":"cve@mitre.org"},{"url":"https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4","label":"cve@mitre.org"},{"url":"https://medium.com/%40jra8908/cve-2019-19576-e9da712b779","label":"cve@mitre.org"},{"url":"https://www.verot.net","label":"cve@mitre.org"},{"url":"https://www.verot.net/php_class_upload.htm","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/getk2/k2/commit/d1344706c4b74c2ae7659b286b5a066117155124","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/jra89/CVE-2019-19576","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/verot/class.upload.php/commit/5a7505ddec956fdc9e9c071ae5089865559174f1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/verot/class.upload.php/commit/db1b4fe50c1754696970d8b437f07e7b94a7ebf2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://medium.com/%40jra8908/cve-2019-19576-e9da712b779","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.verot.net","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.verot.net/php_class_upload.htm","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.2638,"epssPercentile":0.97913,"exploitAvailable":true,"ingestedAt":"2026-06-26T16:43:13.349Z","exploits":{"exploitdb":true,"github":1,"githubRepos":["https://github.com/jra89/CVE-2019-19576"],"checkedAt":"2026-09-23T07:13:15.841Z"},"slug":"CVE-2019-19576","body":"## Overview\n\nclass.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.\n\n## Affected\n\n- `verot < 1.0.3`\n- `verot >= 2.0.0, < 2.0.4`\n- `k2 <= 2.10.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `verot 2.0.4`","depth":"abyssal","depthScore":71,"depthScoreParts":{"impact":53.9,"likelihood":5.3,"exploitation":12,"ransomware":0},"changes":[]}