CVE-2019-16132: Phpok Oklite

Medium severity, CVSS 6.5. EPSS: 6.1% chance of exploitation in the next 30 days.

An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary files via a title directory-traversal pathname followed by a crafted substring.

Affected products

  • Phpok Oklite: version 1.2.25 only

Published 2019-09-09. Last modified 2026-06-17.