Description
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
References (5)
Core 5
Core References
Third Party Advisory x_refsource_misc
https://github.com/xsmo/Image-Uploader-and-Browser-for-CKEditor/pull/11
Third Party Advisory x_refsource_misc
https://github.com/xsmo/Image-Uploader-and-Browser-for-CKEditor/compare/4.1.8...v4.1.9
Patch x_refsource_misc
https://github.com/xsmo/Image-Uploader-and-Browser-for-CKEditor/pull/11/commits/5c7a6b0e10504f08e2f50655541b767e276ce749
Patch x_refsource_misc
https://github.com/xsmo/Image-Uploader-and-Browser-for-CKEditor/commit/c293d38c8b99444e775d94c1af50c9676c6544d2
Various Sources x_refsource_misc
https://visat.me/security/cve-2019-19502/
Scores
CVSS v3
9.8
EPSS
0.0085
EPSS Percentile
75.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
maleck/image_uploader_and_browser_for_ckeditor
< 4.1.9
Published
Dec 02, 2019
Tracked Since
Feb 18, 2026