CVE-2019-19576

CRITICAL

verot.net class.upload <2.0.4 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2019-19576. PoCs published by Jinny Ramsmark, jra89.

AI-analyzed exploit summary This exploit generates a malicious JPEG file with embedded PHP code to achieve Remote Code Execution (RCE) in Verot class.upload.php versions <=2.0.3. It injects a PHP payload into the JPEG file's end-of-file marker, bypassing image validation checks.

Description

class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

Exploits (2)

exploitdb WORKING POC
by Jinny Ramsmark · phpwebappsphp
https://www.exploit-db.com/exploits/47749

This exploit generates a malicious JPEG file with embedded PHP code to achieve Remote Code Execution (RCE) in Verot class.upload.php versions <=2.0.3. It injects a PHP payload into the JPEG file's end-of-file marker, bypassing image validation checks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Verot class.upload.php <=2.0.3
No auth needed
Prerequisites: PHP with GD library installed · Target application using vulnerable Verot class.upload.php · Ability to upload files to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 12 stars
by jra89 · poc
https://github.com/jra89/CVE-2019-19576

This repository contains a functional exploit for CVE-2019-19576, demonstrating arbitrary file upload and remote code execution in class.upload.php <= 2.0.3 via a phar extension bypass and image payload injection.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: class.upload.php <= 2.0.3
No auth needed
Prerequisites: PHP with GD extension · Target system with phar extension enabled
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (10)

Core 10
Core References
Vendor Advisory x_refsource_misc
https://www.verot.net/php_class_upload.htm
Product x_refsource_misc
https://www.verot.net
Patch, Third Party Advisory x_refsource_misc
https://github.com/verot/class.upload.php/compare/2.0.3...2.0.4
Patch, Third Party Advisory x_refsource_misc
https://github.com/verot/class.upload.php/compare/1.0.2...1.0.3
Exploit, Third Party Advisory x_refsource_misc
https://github.com/jra89/CVE-2019-19576
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/155577/Verot-2.0.3-Remote-Code-Execution.html

Scores

CVSS v3 9.8
EPSS 0.2618
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (3)
getk2/k2 < 2.10.1
verot/class.upload.php 0 - 1.0.3Packagist
verot_project/verot < 1.0.3
Published Dec 04, 2019
Tracked Since Feb 18, 2026