CVE-2019-19550

HIGH

Senior Rubiweb <6.2.34.28,6.2.34.37 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-19550. PoCs published by underprotection, redteambrasil.

AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2019-19550, an authentication bypass vulnerability in Senior Rubiweb versions 6.2.34.28 and 6.2.34.37. The exploit involves accessing specific URLs to gain unauthorized admin access to sensitive information.

Description

Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of affected users using vulnerable versions. The attacker only needs to provide the correct URL.

Exploits (2)

nomisec WORKING POC 2 stars
by underprotection · poc
https://github.com/underprotection/CVE-2019-19550

The repository provides a functional proof-of-concept for CVE-2019-19550, an authentication bypass vulnerability in Senior Rubiweb versions 6.2.34.28 and 6.2.34.37. The exploit involves accessing specific URLs to gain unauthorized admin access to sensitive information.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Senior Rubiweb 6.2.34.28, 6.2.34.37
No auth needed
Prerequisites: Access to the target Rubiweb instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WRITEUP
by redteambrasil · poc
https://github.com/redteambrasil/CVE-2019-19550

The repository provides a detailed technical analysis of CVE-2019-19550, an authentication bypass vulnerability in Senior Rubiweb versions 6.2.34.28 and 6.2.34.37. It includes specific URLs to exploit the vulnerability, demonstrating an incorrect access control issue that allows remote access to sensitive information.

Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Senior Rubiweb 6.2.34.28, 6.2.34.37
No auth needed
Prerequisites: Access to the target URL
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0192
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (2)
senior/rubiweb 6.2.34.28
senior/rubiweb 6.2.34.37
Published Jan 31, 2020
Tracked Since Feb 18, 2026