CVE-2019-9002

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/02/2019
Last modified:
17/06/2026

Description

An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tiny_issue_project:tiny_issue:1.3.1:*:*:*:*:*:*:*
cpe:2.3:a:pixeline:bugs:*:*:*:*:*:*:*:* 1.3.2c (including)