Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
References
Configurations
History
No history.
Information
Published : 2019-12-02 16:15
Updated : 2024-02-04 20:39
NVD link : CVE-2019-19502
Mitre link : CVE-2019-19502
CVE.ORG link : CVE-2019-19502
JSON object : View
Products Affected
maleck
- image_uploader_and_browser_for_ckeditor
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')