7.5
CVSSv2

CVE-2019-19502

Published: 02/12/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor prior to 4.1.9 allows remote authenticated users to execute arbitrary PHP code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

maleck image uploader and browser for ckeditor