← back
CVE-2019-19609observed exploitation

CVE-2019-19609

57Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 54%
from disclosure to weapon633 days
Published on NVDDec 5
1st PoC+633d
VulnCheck+1202d
exploitation probability
54%top 1% of all CVEs
observed exploitation
yesVulnCheck
17 public exploit(s)
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell commands to be executed by the execa function.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.