7.5
CVSSv2

CVE-2019-9002

Published: 22/02/2019 Updated: 21/07/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in Tiny Issue 1.3.1 and pixeline Bugs up to and including 1.3.2c. install/config-setup.php allows remote malicious users to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tiny issue project tiny issue 1.3.1

pixeline bugs