Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
References
Configurations
Information
Published : 2019-12-02 08:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-19502
Mitre link : CVE-2019-19502
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
maleck
- image_uploader_and_browser_for_ckeditor