CRITICAL

CVE-2019-5128

CVSS v3

9.8

CRITICAL

EPSS Score

92.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.

Technical details

Published
10/25/2019

Frequently asked questions

What is CVE-2019-5128?

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.

Is CVE-2019-5128 actively exploited?

Active exploitation of CVE-2019-5128 has not been confirmed. The EPSS score is 92.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-5128?

CVE-2019-5128 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-5128 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.