CVE-2019-16131: Phpok Oklite

High severity, CVSS 8.8. EPSS: 6.5% chance of exploitation in the next 30 days.

framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file from a ZIP archive can be written to /data/cache/.

Affected products

  • Phpok Oklite: version 1.2.25 only

Published 2019-09-09. Last modified 2026-06-17.