CVE-2019-5123: Youphptube
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.
Affected products
- Youphptube Youphptube: version 7.6 only
Published 2019-10-25. Last modified 2026-06-17.