CVE-2019-19502

CRITICAL

maleck/image_uploader_and_browser_for_ckeditor < 4.1.9 - Authenticated PHP Code Injection in pluginconfig.php

Title source: llm
STIX 2.1

Description

Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.

Scores

CVSS v3 9.8
EPSS 0.0192
EPSS Percentile 77.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
maleck/image_uploader_and_browser_for_ckeditor < 4.1.9
Published Dec 02, 2019
Tracked Since Feb 18, 2026