CVE-2019-19020

HIGH

TitanHQ WebTitan < 5.18 - Authenticated Arbitrary File Write via Backup File Upload

Title source: llm
STIX 2.1

Description

An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a crafted backup file that enables an attacker to execute arbitrary code by overwriting existing files or adding new PHP files under the web root. This requires the attacker to have access to a valid web interface account.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://write-up.github.io/webtitan/
Release Notes, Vendor Advisory x_refsource_misc
https://www.webtitan.com/resources/product-updates/

Scores

CVSS v3 7.2
EPSS 0.0233
EPSS Percentile 81.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
titanhq/webtitan < 5.18
Published Dec 02, 2019
Tracked Since Feb 18, 2026